Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up

BGP RPKI Route Origin Authorization (ROA) & Hijack Defense Studio

Resource Public Key Infrastructure, BGP Route Origin Validation (ROV), Subprefix Hijack Defense, and RTR Protocol

The global Internet routing fabric relies on BGP, an unauthenticated protocol historically vulnerable to catastrophic traffic hijacks. RPKI Route Origin Validation (ROV) provides cryptographic proof that the Autonomous System (AS) originating an IP prefix has legal authorization from the Regional Internet Registry (RIR), stopping BGP hijacks at the network edge.

1. BGP Route Hijack & RPKI Validation State Machine

Simulate Legitimate vs Attacker Route Announcements and Test Edge ROV Filtering
Legitimate Origin (Cloudflare / Bank)
Signed ROA in RIR Repository
ROA AUTHORIZED
Origin ASN: AS13335
Covered Prefix: 104.16.0.0/20
Authorized MaxLength: /20
Incoming BGP Announcement
Received from Upstream Peer / Transit
INVALID
Announced Prefix: 104.16.0.0/24
Originating AS_PATH: AS666
BGP Route Disposition: DROPPED (Filtered)

2. ROA Cryptographic Prefix & MaxLength Sizer

Analyze RFC 9319 Security Tradeoffs: Operational Agility vs Subprefix Vulnerability

3. Production Router Configurations & RTR Daemons

Production BIRD 2, FRRouting (FRR), and Routinator Deployment Templates

Frequently Asked Technical Questions

What is BGP Route Hijacking and why is BGP inherently vulnerable to it?+
The Border Gateway Protocol (BGP) was designed in 1989 on implicit trust: any Autonomous System (AS) can announce any IP address prefix to the global routing table without cryptographic proof of ownership. In a BGP hijack, an attacker (or misconfigured ISP) announces an IP prefix belonging to another organization. Because BGP routing algorithms prioritize the "longest-prefix match" (e.g. a /24 announcement wins over a legitimate /20 announcement) or shorter AS_PATH lengths, global Internet routers will divert traffic to the illegitimate destination, enabling traffic interception, eavesdropping, and total denial of service.
How does Resource Public Key Infrastructure (RPKI) and Route Origin Validation (ROV) prevent hijacks?+
RPKI creates a hierarchical Public Key Infrastructure rooted in the five Regional Internet Registries (RIRs: ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC). Certified IP address holders sign Route Origin Authorizations (ROAs)—cryptographic objects specifying the authorized Origin Autonomous System Number (ASN) and the maximum allowed prefix length (MaxLength). Border routers run Route Origin Validation (ROV): when receiving an incoming BGP route announcement, the router queries an RPKI cache over the RTR protocol (RFC 8210) and marks the route as Valid, Invalid, or NotFound. If the route is marked Invalid, modern network policy automatically drops the announcement.
What is the "MaxLength Dilemma" in ROA creation?+
When an organization creates a ROA for a /20 prefix, setting MaxLength to /24 gives operational agility (allowing the network to announce sixteen /24 subnets for traffic engineering without updating the ROA). However, this creates a major vulnerability: an attacker can announce a forged-origin /24 using the legitimate ASN in the AS_PATH. Because the announcement matches the ROA ASN and does not exceed MaxLength, ROV evaluates it as Valid! Security best practice (RFC 9319) recommends matching the prefix length exactly (e.g. /20 without a loose MaxLength) and generating separate ROAs for specific subnets.
What is the RPKI-to-Router (RTR) Protocol (RFC 6810 / RFC 8210)?+
Border routers lack the computational CPU and memory required to download and cryptographically verify gigabytes of X.509 RPKI certificates, manifests, and CRLs across the global Internet. Instead, dedicated RPKI validating daemons (such as Routinator, StayRTR, or OctoRPKI) perform the cryptographic verification out-of-band and distill the cryptographic state into a simple table of (ASN, Prefix, MaxLength) tuples. The validator then synchronizes this clean table with border routers over a lightweight binary TCP session called the RPKI-to-Router (RTR) protocol.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement