Abstract:
The Resource Public Key Infrastructure (RPKI) is an essential technology for securing the Border Gateway Protocol (BGP) routing on the Internet. Although the global RPKI-...Show MoreMetadata
Abstract:
The Resource Public Key Infrastructure (RPKI) is an essential technology for securing the Border Gateway Protocol (BGP) routing on the Internet. Although the global RPKI-ROV (Route Origin Validation) rate of unique Prefix-Origin Pairs(IPv4) has been improved from 17% in June 2019 (pre-pandemic) to 41.12% in March 2023 (post-pandemic) [1] – [3], the overall RPKI-ROV rate remains below 50%. This indicates a significant insufficiency in RPKI-ROV deployment for ensuring secure BGP routing and persistent security challenges continue to persist in the Internet. To address this, we first develop software to analyze and visualize the relationships among Autonomous Systems (ASes), degree distribution, and their RPKI validation status, given a region in IL. Next, we investigate the RPKI validation rates along real-time routing paths from Peoria, IL to all 50 states in the USA. Based on the analysis, we propose a novel lightweight, decentralized, easy-to-deploy, offline protocol called Comp-RPKI, which aims to complement and address the partial deployment of RPKI. Comp-RPKI aims to ensure every segment of a routing path is validated either through online RPKI or secured by offline Comp-RPKI, thereby achieving full RKPI-ROV coverage and enhancing BGP security.
Date of Conference: 04-06 August 2023
Date Added to IEEE Xplore: 07 February 2024
ISBN Information: