Resource Public Key Infrastructure (RPKI)
WHAT IS RPKI?
RPKI is a robust security framework for verifying the association between resource holders and their Internet resources via resource certification. In this context, 'resource holders' are organizations such as Regional Internet Registries (RIRs), Internet Service Providers (ISPs), or end-user organizations, while 'Internet resources' are IPv4 and IPv6 address blocks and Autonomous System Numbers (ASNs). This has been an initiative that has been developed within the IETF's SIDR Working Group and among the various RIRs.
WHAT IS A RESOURCE?
A resource is any grouping of Internet addresses or ASNs; numbers that describe a computer or a network’s location. Routers use these numbers much like postal services use street and house numbers to define where people live.
WHAT IS A CERTIFICATE?
Much like a lease being proof that you are allowed to use an apartment or house, a resource certificate is an electronic file that serves as proof that a resource has been assigned to an individual or company for their use. These certificates list a collection of Internet number resources (IPv4 addresses, IPv6 addresses, and ASNs) that are associated with a holder of those resources. Certificates provide a means of third-party validation of assertions related to resource allocations using proven cryptographic algorithms.
WHY IS RPKI NEEDED?
The majority of network relationships on the Internet are based on a system of mutual trust. Each party trusts that the route used to transmit information is safe, accurate, and will not be maliciously altered. This trust model proved adequate in the early stages of Internet development, but is increasingly open to potential abuse and attack as the Internet encompasses a markedly larger and very much more diverse population.
There is an urgent need to make this system more robust before a routing event occurs that causes major, widespread problems. As the unallocated pool of IPv4 addresses runs out, two issues will likely emerge:
- The number of people hijacking address space will grow
- The incentive for people to sell any unused or underutilized blocks of IPv4 address space they hold will increase, but potential buyers have no way of knowing if the seller is actually the legitimate holder of the resources.
Both of these issues can be solved by RPKI. By digitally verifying that a resource has been allocated or assigned to a specific certificate holder, RPKI allows prefix holder checking to be automated in a dependable, transparent and standardized way, using Route Origin Authorizations (ROAs). This is often referred to as "automated provisioning", and can play an important role in securing the routing system.
When Internet resources are transferred between two parties, certificates will make this transaction reliable and secure, because the recipient can be sure that the resources have been legitimately allocated or assigned by an RIR.
HOW DOES RPKI AFFECT ME?
It is envisioned that ISPs and network operators will use resource certificates to help verify the accuracy of routes on the Internet and to prevent fraudulent misdirection of Internet traffic. Resource holders with resource certificates will greatly enhance the security of their Internet presence by providing a cryptographically secure means to determine fraudulent or mistaken Internet routes.
For more information on resource certification, ARIN recommends reading Geoff Huston’s article on the Internet Society’s website.
WHAT IS ARIN DOING WITH RPKI?
On 1 July 2009, ARIN made its RPKI pilot program available to the community. As a result of an extensive review in preparation for offering a production service, ARIN has determined that additional functionality must be added to the service architecture to mitigate specific security concerns and that there is a need for community feedback about the nature of this service. ARIN has received support for deployment, is currently working on development to satisfy requirements, and will soon announce an anticipated production release date in 2012.
ARIN'S RPKI PILOT
Using a rebranded version of RIPE’s code, ARIN’s RPKI pilot program is a standalone system that will allow various ISPs that receive resources from ARIN to request certificates for their IPv4 and IPv6 Provider Aggregatable (PA) resources and manage Route Origin Authorizations (ROAs). This system also provides a Pilot Repository of certificates and ROAs, and handles key rollovers/revocations.
Note: this system is not linked to ARIN’s production system in any way.
This pilot will be available until ARIN’s RPKI production service is rolled out, which is anticipated to be in 2012. It is available for users to experiment with and to research operational aspects of the system.
HOW TO USE THE RPKI PILOT
ARIN strongly encourages members of the community to join the RPKI pilot, create ROAs, and experiment with software available through various vendors. This system provides a venue for valuable feedback to ARIN and the standards community. To participate in the pilot program, simply request an account at https://rpki-pilot.arin.net.
ARIN will strive to make this pilot program available at all times. However, unknown issues or problem reports may necessitate unannounced outages of the service. If you are unable to access this service, please wait for a period of time and try the system again later. ARIN also encourages all RPKI pilot users to subscribe and participate on the arin-tech-discuss@arin.net mailing list.
Through ARIN’s pilot, users may create ROAs and view certificates of resources that have been taken as a snapshot from ARIN’s database. These secure certificates may be seen through ARIN’s Pilot Repository. Using these certificates, users may then begin researching Origin Validation for their announcements.
Note: When linking an Autonomous System (AS) to routing origin announcements, prefix the AS number with “AS”. For example, if the origin AS is 64512, input it as AS64512 within the form.
There are many tools available which will help fetch the objects generated from ARIN’s Pilot Repository that may then be validated. Some of these include:
- RIPE RPKI Validator toolset
- RPKI.net rcynic Validation Tool
- RPSTIR - BBN Validation Tool
- RTRlib - The RPKI-Router Client C Library
- BGP Secure Routing Extension (BGP-SRx) – RPKI for Quagga
- RPKI Origin Validation Looking Glass
Users looking to bootstrap this information will need to use ARIN’s Trust Anchor Locator (TAL), contained below:
rsync://rpki-pilot.arin.net:10873/certrepo/e8/29afd2-319c-428f-b6b0-3528a7d24dcd/1/4789Xt9H2ltHuAXdrQ6GWXWH2Ao.cer
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAgx/qMyRxeuWrnyHvrwZm
X5GtTLGTkWEf3MojT1dgeOQ/iMZ4F/vWYClUJXYrNoiJnjWyjpkMwjlJmyL/1eGd
Qjw+U0T9fJN3+QNOxZTMX0Kg6Ch5O/y+7z/qTQTMoSlrofYt/8YT/bhyBzKeih8G
PX2oW58OnuAEEBY7k+8vv47RDFRqtpTTU21YXPc1hlzKeoWGs8HPq4qZyTlY6lob
d55Rc4isi6p7C+424MOnfJJHv2UJlv+Z1UATHCa7BqkJ/aEN82e1Q8IVCSDlSE6Y
ykykABn711q/Rg9CPzZmkq1kFhodnK4ICkPMZksv2u0O+HDKs3Zn/SLZqPk6r1ga
+wIDAQABNote: When ARIN’s production service is operational, it will have a new TAL. This TAL will only be available via download after acknowledging the CPS and terms of service.
RPKI AT THE OTHER RIRs
Public statements made about RPKI by the Number Resource Organization (NRO) over the past 12 months set a date of 1 January 2011 for deployment by the five Regional Internet Registries (RIRs). Various complexities in different regions have altered the anticipated public deployment schedules for several RIRs, including ARIN. Other RIRs began phased deployments in January 2011.
More information about RPKI at other RIRs is available at the following URLs:
Additional Information
Relevant Links
Registration Services Help Desk
Monday through Friday
7:00 AM to 7:00 PM ET
Phone: +1.703.227.0660
Fax: +1.703.227.0676
Email: hostmaster@arin.net
Tips for Calling the Help Desk

