Tracking time delays in the RPKI-based Route Origin Validation supply chain

April 13, 2023

Tracking time delays in the RPKI-based Route Origin Validation supply chain

By Amreesh Phokeer – Internet surveyor at Internet Society

What is the life cycle of Resource Public Key Infrastructure (RPKI) data used to secure Internet routing? More specifically, how long does a Route Origin Authorization (ROA) take to propagate, and how quickly does it actually affect Internet routing and reachability?

These are questions that network operators would love to have answers to, given that changes on the RPKI management plane can impact how traffic flows to or from their networks. I recently collaborated on a project, RPKI Time-of-Flight: Tracking Delays in the Management, Control, and Data Planes, to answer these questions by dissecting the stages in the life of RPKI data.

Below is a summary of the RPKI lifecycle and our findings.

(Free access, no subscription required)

Key points: Creation times vary significantly across the Regional Internet Registries (RIRs), ranging from a few minutes to over an hour for new ROAs to reach the publication points.High publication delays were initially observed for ARIN and LACNIC due to a time zone issue. The problem has been reported and is now fixed. Observed delays are usually less than 20 minutes.Relying Party (RP) delay represents the most time-consuming step observed in ROA processing.Deleting ROAs takes longer to reflect in BGP as routers explore alternate routes that have not yet been invalidated.

ROV supply chain

Publishing ROAs is complex. The process involves several players, is not instantaneous, and is often dominated by ad hoc administrative decisions.

It starts when a resource holder queries an RIR to create or update RPKI information for its prefixes. The ROAs and other meta files (manifests, CRLs) are then placed in public repositories called publication points.

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments