Skip to main content

Topic

RPKI and Route Security

Within the Topic facet, RPKI and Route Security topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

A single amber diagnostic pulse reaches a bank of BGP routing equipment in a dark blue-green network operations room.

Story

A Scan Found 4,611 Exposed BGP Routers in APNIC. It Cannot Say Why They Were Open

At APNIC 62, researchers put a regional number on a quiet control-plane problem: 4,611 routers across 1,343 APNIC-region autonomous systems answered an unsolicited BGP OPEN exchange in a February IPv4 scan. That is firmer evidence than a port banner, but it is neither a breach…

Sep 9, 2026
Two intact repository towers exchange cyan data through a closed glass gate above amber lines leading to unlabelled dependency nodes.

Story

ARIN’s RPKI Failover Test Left the Dependency Question Open

ARIN blocked access to its RPKI repositories for an hour, restored it, confirmed redundancy five minutes later and reported a return to baseline after another fifteen. That is unusually concrete resilience evidence. It is also narrower than the dependency question ARIN had…

Sep 8, 2026
A lit network appliance connects to a blank credential card beside an hourglass with sand collected below.

Global Institutional Trends

The RPKI Lab Restarted. Its Recovery Was Still Unconfirmed

A September follow-up moves the question beyond turning services back on: what proves recovery after a signed credential's lifetime has elapsed?

Sep 8, 2026
A search beam follows two technical coordinate paths toward a network record whose orange label sits above a stable brass handle.

Story

ARIN Lets You Name a ROA. Its Online Search Still Ignores the Name

ARIN Lets You Name a ROA. Its Online Search Still Ignores the Name intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The…

Sep 7, 2026
Абстрактные маршрутизатор и кэш обмениваются голубыми сигналами под исчезающими индикаторами, а янтарная полоса внизу сохраняет последовательность свидетельств

IETF

RPKI Router YANG Draft Names New Failure Counters. A Snapshot Is Not a History

A planned cache restart and a cache shutdown can both leave a router without a live RPKI feed. They demand different responses. A revised SIDROPS data model now gives operators more precise counters for that distinction. The harder governance task begins after collection…

Sep 7, 2026
Nested luminous address-prefix lanes cross a dark network workbench, where an amber boundary ruler stops at a gap between a sealed completion card and a transparent five-row test tray.

Story

ARIN Closed the ROA Wording Fix. The Published Example Drops the Mask Interval

ARIN answered a precise operator complaint in five weeks and marked the documentation repair complete. That is the constructive part of the record. The harder question is why the live example no longer contains the length boundary that made the requested correction capable of…

Sep 7, 2026
Two equivalent cyan signal paths meet a mechanical parsing gate; only the path with one leading bead passes into a glass prism and intact data tiles.

Story

Barry’s README Uses the IPv6 Prefix Its Lexer Rejects

`::/0` and `0::/0` name the same IPv6 address space. In LACNIC’s experimental Barry generator, the first spelling is documented as a default yet an open issue says it stops at the descriptor lexer; adding one zero lets the token proceed. That is not an RPKI validation failure. It…

Sep 6, 2026
A luminous staged ROA object branches toward an instrumented review chamber and a sparse machine conduit, while two separate observation beacons feed a small advisory bridge.

Story

ARIN Plans ROA Impact Warnings for the Web, Not the API

ARIN is building a warning for the moment before a Route Origin Authorization changes what observed routes look like. The warning belongs to its web interface. The registry’s programmatic writer is still expected to assemble the same evidence elsewhere. That is not a difference…

Sep 6, 2026
A three-part validation token crosses an internal router link while a separate amber policy gate remains under the receiving router’s control.

IETF

An Origin Validation Community Carries a Trust Decision Without Delegating Import Policy

An Origin Validation Community Carries a Trust Decision Without Delegating Import Policy intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences…

Sep 5, 2026
A stylized route-origin authorization passes through cryptographic validation gates into a resilient routing network.

Story

LACNIC’s RPKI controls make route origin authority operable

LACNIC’s RPKI controls make route origin authority operable intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Story…

Sep 5, 2026
A bounded cluster of authorized provider links joins a longer AS path that continues outside the attestation frame.

Number Resource Society

An ASPA Is Not a Complete AS-Path Attestation

An ASPA can help an operator test whether an AS path is consistent with published customer-to-provider authorizations. That is valuable route-leak evidence. It is not a signature over every hop, a proof of route origin, a commercial contract, or a guarantee that the published…

Sep 5, 2026
One repository feeds two healthy RPKI validators with different validated sets, which a central policy switch assigns to separate router groups.

Global Regional ISP Trends

When RPKI Validators Disagree, Redundancy Becomes a Policy Choice

Two healthy validators can give different answers about the same prefix. The moment an operator chooses which answer reaches a router, validator redundancy stops being a box-counting exercise and becomes a routing-policy decision.

Sep 5, 2026
Two separate RPKI cache appliances flank a wall clock and synchronization receipt ledger, illustrating that each serial belongs to its own session.

Number Resource Society

An RPKI Cache Serial Is Not a Freshness Timestamp

Two RPKI caches can report perfectly accurate serial numbers and still tell an operator nothing about which cache holds newer global data. RFC 8210 scopes a serial to one cache session and protocol version. Treating the larger number as the fresher view manufactures a chronology…

Sep 5, 2026
Editorial illustration of a bounded IP prefix block with one authorized emergency route highlighted.

Global Regional ISP Trends

A ROA maxLength Is Not a Traffic-Engineering Permission

A broad ROA can keep an emergency more-specific from becoming RPKI-invalid. It can also authorize origins that nobody intended to announce. The operating control is the exact origin plan, not the convenience of one large `maxLength`.

Sep 5, 2026
A broad ROA authorization tree is separated from a smaller set of selected operational network routes by layered evidence checks.

Number Resource Society

A ROA maxLength Is Not a Traffic-Engineering Policy

A route can be RPKI Valid because a ROA’s maxLength admits its prefix length. That result proves a bounded origin authorization. It does not prove that the more-specific route was planned, approved, currently announced or preferred by the operator. Those are separate facts, and…

Sep 5, 2026
Layered routing-security illustration separating a BGPsec router certificate and signing key from prefix-origin authorization and observed route paths.

Number Resource Society

A BGPsec Router Certificate Is Not Route-Origin Authority

A BGPsec Router Certificate Is Not Route-Origin Authority intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Number…

Sep 5, 2026
A signed contact object branches into separate checks for channel reachability, human acknowledgement, authority and escalation, with one failed path.

Number Resource Society

A Ghostbusters Record Is Not an Incident Command Roster

An RPKI relying party can validate every byte of a Ghostbusters Record and still not know whether anyone is watching the listed channel when action is needed. The signed entity solves discovery of minimal CA-maintainer contact data; operational accountability begins where that…

Sep 4, 2026
Current and successor RPKI trust-anchor keys connected by reciprocal verification, with validators adopting the successor in stages and a separate legacy TAL path.

Number Resource Society

A Trust Anchor Rollover Needs an Acceptance Ledger

An RPKI trust-anchor operator can publish a successor key without making every relying party ready to use it. The transition is a sequence of verified observations, not a launch date: a defensible record must show what was announced, what remained stable, which validators crossed…

Sep 4, 2026
A signed RPKI object set moves from a commit chamber through manifest and RRDP layers to independent observation nodes.

Number Resource Society

An RPKI Publication Point Needs a Commit-to-Visibility Ledger

An RPKI publication server can accept an authenticated update atomically while relying parties still hold an earlier repository view. That is not necessarily a contradiction or a failure. It is a boundary between different authorities, protocols and observation times. A useful…

Sep 4, 2026
A luminous routing-identity token crosses between two control stations above a layered evidence ledger.

Number Resource Society

An ASN Transfer Needs a Routing-Identity Handover Ledger

An ASN Transfer Needs a Routing-Identity Handover Ledger intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Number…

Sep 4, 2026