Plenary - Main Room (Tue, 11:00)
This is a draft agenda: changes are still being made.
In this presentation, we investigate how fast the data plane converges when
RPKI security attestations change. Our method covers all RIPE IP prefixes
that are part of the RPKI hosted model and allows us to study the full
propagation timeline. Our results reveal that RPKI propagation is at least
one order of magnitude slower than plain BGP. Invalid-to-valid transitions
require 9–12 minutes, valid-to- invalid transitions need 30–42 minutes to
be effective at 50% of our vantage points.
Furthermor…
Network operators use customer AS-SETs and Internet Routing Registry (IRR) route objects to construct prefix filters, and Resource Public Key Infrastructure (RPKI) data to validate route origins. These sources represent different forms of routing evidence and may produce conflicting results for the same BGP announcement.
We present a time-aligned comparison of BGP, IRR, and RPKI from 8–14 August 2026. The analysis covers public BGP prefix-origin pairs observed by 57 RIPE RIS and RouteViews coll…
The Resource Public Key Infrastructure (RPKI) is the primary defense against BGP route misorigination.
It offers a shield against origin hijacks, flavors of route leaks, and misconfigurations.
Since its deployment in 2011, the adoption of RPKI by Internet Service Providers has shown continuous growth, a trend that persists to this day.
As this growth continues it is important to measure its effect on BGP stability.
BGP is a chatty protocol with many updates that can result from a single configu…