Topic
RPKI and Route Security
Within the Topic facet, RPKI and Route Security topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

ICANN
Interim Service Before Derecognition
The registry system should be able to keep allocations, registration records, reverse DNS, and routing-security services available without first deciding which institution deserves to survive a governance crisis. Transferable continuity must exist before recognition is withdrawn…

ICANN
The NRO's Joint RPKI Trust and the Concentration Beneath Five Logos
RPKI resilience is often described through five regional brands, five portals and five trust anchors. That is the wrong unit of analysis. A serious test measures failure domains: common governance, common recovery assumptions, shared program direction, validator dependence…

ICANN
The NRO Executive Council and the Closed Coordination Layer
The Number Resource Organization Executive Council is small enough to coordinate quickly and powerful enough to shape the environment in which public number policy is later debated. That combination may be operationally necessary. It is also why the council's agenda, costs…

ICANN
NRS Recognition by Proof, Not Patronage
Number Resource Society should not ask the Internet to accept a new numbering-service model merely because incumbents bless it, opponents fear it or supporters repeat the language of reform. As a global nonprofit advocacy and membership organisation, NRS can make the harder case…

Story
NRS Advocacy for a Portable Trust-Anchor Model
Number-resource recognition should survive a change of registry, certificate authority, repository or corporate form without forcing a holder to begin its history again. Number Resource Society can advocate this continuity and scrutinise the institutions responsible for it; NRS…

Story
Data Accuracy SLAs the RIRs Do Not Publish
An address record can remain reachable while being wrong, and a registry service can meet every uptime target while the wrong answer continues to circulate. Public dependence on number-resource data now deserves correction commitments measured from a reported defect to a verified…

Story
Publication-as-a-Service and the New Middleman
Running an RPKI certificate authority no longer requires running the repository from which validators retrieve its entities. That separation can reduce a network operator's infrastructure burden and place global distribution with a specialist. It also inserts a service provider…

Story
Delegated RPKI and the Right to Hold Your Own Keys
Delegated RPKI promises that a resource holder can operate its own certification authority and retain the private key used to sign routing authorizations. The promise is technically substantial but institutionally incomplete. Key autonomy is usable only when the option is…

Story
RPKI MaxLength and the Cost of a Typo
A single prefix-length choice can turn an intended routing authorization into evidence that a legitimate route is unauthorized. The error then travels through certificates, repositories, validators and the policies of networks the resource holder cannot direct. Calling this user…

Story
AS0 ROAs: Conservation Tool or Pre-Emptive Denial?
An AS0 ROA says that a prefix and its more-specifics should not be used for public routing. Applied to genuinely unallocated space, it can turn a registry's conservation duty into a machine-readable warning against misoriginations. Applied to a wrongly classified or newly…

Story
RPKI-to-Router Deployment and the Missing Governance Layer
RPKI can tell a router that a route origin is Valid, Invalid or NotFound, but it does not command the router to carry or reject the route. Between a registry's signed statement and a packet's path sits a succession of validators, caches, router implementations, peering contracts…

Story
RPKI Terms of Service Versus Routing Liability
When a registry-controlled certificate or published authorisation changes a legitimate route from Valid to Invalid, networks that reject Invalid announcements can make the error economically real within minutes. Terms that give an institution decisive certificate powers while…

Story
The RPKI Repository Outage That Policy Reports Miss
An RPKI repository is not available merely because its operator can reach a server. It is available when independent relying parties can fetch a complete, current and cryptographically coherent view before relevant certificates, manifests or revocation lists expire, and when that…

Story
Validator Diversity Cannot Cure a Single Trust Anchor
Three independent validators can parse the same RPKI hierarchy, reject malformed objects in different code and survive different software failures. Yet if all three begin with the same trust-anchor key for a resource, they inherit the same upstream certification decision.…

Story
The ROA That Survived a Transfer Too Long
A number-resource transfer can be complete in the registry and still unfinished in routing authority. The dangerous interval begins when the recognised holder changes but validators continue to accept an old Route Origin Authorisation, or when the old authority disappears before…

Story
Hosted RPKI and the Convenience Trap
Hosted RPKI turns a difficult security function into a few choices in a registry portal. That is a genuine public benefit. It also places the certificate key, signing service, publication system and revocation path close to the same registrar that controls resource records.…

Story
A Certificate Authority Above the Operator
A Certificate Authority Above the Operator intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Story intelligence…

Story
The Operator's Option Value in an Idle Prefix
A prefix can disappear from the global routing table without disappearing from an operator's plans. It may be staged for a migration, reserved for growth, held behind a failover design, provisioned at a cloud edge but not yet announced, or simply left fallow without a credible…

Story
The Price of a Clean /16 Is Not the Price of Every /16
Two IPv4 /16s each contain 65,536 addresses. That arithmetic does not make them economically interchangeable. A defensible price must disclose the chain of recognised holdership, prior use, reputation evidence, subdivision, transfer path, routing state, RPKI and route-object…

Story
Fractional Ownership Meets an Indivisible Prefix
Joint investment can finance scarce IPv4 capacity, but a percentage interest cannot configure a router, maintain a registry account or sign a route authorization. The workable bargain separates divisible economic claims from one accountable operating mandate, then makes that…
