Summary
- As commercial backbones multiplied, the Routing Arbiter and its database gave autonomous networks a common, machine-readable place to publish routing intentions across organizational boundaries.
- Elise Gerich helped lead that institutional transition, but the registry was a collective achievement and never a source of automatic truth: identity, authority, freshness and comparison with observed routing remained separate problems.
Two network operators can exchange BGP updates while disagreeing about the relationship those updates are supposed to express. One may intend to announce only customer routes; the other may expect a wider set. Each can install filters, but a filter is a local decision hidden inside a router. When the expected and accepted routes do not match, the packet loss appears at an organizational boundary and the reason can be difficult to see from either side.
That information problem grew sharper as the American research backbone ceased to be the Internet’s organizing center. NSF’s transition plan anticipated multiple commercial network service providers connected at shared exchange points. Competition moved carriage into private hands, but it did not remove the need for a common view of who intended to send what to whom. A market in backbone service could fragment operational knowledge even while the protocol preserved technical reachability.
Elise Gerich worked at Merit through this change. The Internet Hall of Fame records her role in NSFNET’s T1 and T3 expansions and identifies her as a co-principal investigator for Routing Arbiter Services. Merit’s history says that NSF awarded the early Routing Arbiter work jointly to Merit and USC ISI in 1994. The principal products included Route Servers and the Routing Assets Database, later known as RADb. The proper unit of credit is therefore a programme and a community: NSF, Merit, ISI, RIPE contributors, engineers, providers and operators.
Gerich’s significance lies in helping turn their coordination problem into a durable public service, not in inventing every component alone.
RFC 1786 exposes the mechanism. Gerich was one of seven authors of the 1995 document, which generalized RIPE’s earlier policy notation with work carried out at Merit. BGP could help a router filter announcements according to a policy, the authors observed, but it did not publish or communicate that policy. Operational coordination and fault isolation required another layer. The document represented routing as two related choices: what one autonomous system announces to a neighbour, and what the neighbour accepts. Ideally they agree. In practice they may not.
A routing registry made those choices inspectable. Instead of leaving an operator’s intent in telephone calls, private mail or device-specific configuration, a structured object could describe an autonomous system, its import and export rules, its peers and sets of routes or networks. The later Routing Policy Specification Language gave this record a standard grammar. Repositories made the objects queryable; tools could analyze them, compare requirements and generate parts of router configurations or filters. Public did not mean that commercial agreements became public in full.
It meant that the policy claims needed for inter-domain coordination could be found in a shared syntax.
That was a governance innovation as much as a technical one. Rival providers did not have to surrender control of their routers to a central authority. Nor did a registry dictate the commercial terms of peering or transit. It separated publication from enforcement: each network retained the right to decide locally, while a neutral record made incompatible expectations easier to detect and discuss. The shared surface reduced the advantage of private knowledge without erasing organizational autonomy.
The distinction between a route and a statement about a route is essential. A registry object says that a maintainer asserts a prefix should originate from an autonomous system, or that a network intends a certain import or export policy. It does not itself show that the prefix is being announced now, that another network accepts it, or that a router installed it. A declaration can be useful before it becomes observable; it can also be wrong after reality has changed.
The IRR’s later history makes that weakness concrete. RFC 2725 describes records left behind after routes were withdrawn, networks were renumbered or origins and adjacencies changed. RFC 7682 notes that users have strong incentives to register new information when a provider builds filters from it, but weaker incentives to remove harmless old entries. A third party may be unable to identify which repository is authoritative. Mirrors can omit a source, lag behind it or reproduce an assertion whose original authorization was weak.
Automation magnifies both sides of the bargain: accurate records can eliminate repetitive configuration work, while deleting or trusting the wrong object can cut off legitimate reachability.
Authentication and observation therefore belong beside publication, not inside the same box. Later specifications strengthened authorization and proposed cryptographic signatures for RPSL objects. RPKI can let a resource holder authorize an autonomous system to originate a prefix. That is valuable, but RFC 7682 cautions that origin authorization does not express the full set of nuanced import, export and grouping policies available in RPSL. Neither an authorized origin nor a well-formed policy statement proves the route visible on the live Internet.
The evidence chain has distinct links: who controls the resource, who made the statement, when it was refreshed, what a network configured and what collectors or neighbours observed.
Seen this way, Gerich’s contribution is not a heroic claim that a database made the commercial Internet safe. It is an institutional lesson about plural infrastructure. When no operator owns the whole system, coordination depends on artifacts that can cross company boundaries without becoming commands from a central operator. The Routing Arbiter supplied places and tools for publishing, querying and using routing intentions. Its limitations reveal the conditions under which such a record deserves reliance.
The lesson travels beyond routing. Cloud dependencies, software supply chains and AI infrastructure all contain private decisions with public consequences. A shared registry can make those decisions contestable, but only if its records carry provenance, named authority, update expectations and a way to compare declaration with behaviour. A field that merely exists is not accountability. A record becomes governing infrastructure when participants know who can change it, which version controls a decision, how conflicts are surfaced and what happens when it is stale.
Gerich’s chapter in Internet history is therefore about making independence legible. Competing networks did not remain one Internet because they all trusted one operator. They remained capable of coordination because private routing decisions could acquire a public, machine-readable form. The registry was neither the route nor the truth. It was the place where an intention became visible enough to be checked.
Sources
- https://docs.db.ripe.net/RPSL-Object-Types/Descriptions-of-Primary-Objects
- https://nsarchive.gwu.edu/document/19098-national-security-archive-national-science
- https://www.internethalloffame.org/inductee/elise-gerich/
- https://www.merit.edu/research/projects/the-routing-arbiter-project/
- https://www.radb.net/
- https://www.rfc-editor.org/rfc/rfc1786.html
- https://www.rfc-editor.org/rfc/rfc1787.html
- https://www.rfc-editor.org/rfc/rfc2622.html
- https://www.rfc-editor.org/rfc/rfc2650.html
- https://www.rfc-editor.org/rfc/rfc2725.html
- https://www.rfc-editor.org/rfc/rfc4012.html
- https://www.rfc-editor.org/rfc/rfc7682.html
- https://www.rfc-editor.org/rfc/rfc7909.html
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
