Migration of the LACNIC RPKI Core

July 2, 2024

Migration of the LACNIC RPKI Core

By Jorge Cano, Senior Software Architect at LACNIC

The evolution of the LACNIC RPKI (Resource Public Key Infrastructure) and our organization’s ongoing commitment to improving Internet infrastructure security have led to significant progress in implementing RPKI in the region, laying the foundation for a more secure and stable future for Internet routing. Over the last three years, our organization has devoted considerable effort to changing RPKI to strengthen the resource certification process in the region.

We have helped increase global routing security by using Resource Certificates and Route Origin Authorizations (ROAs), promoting resource certification.

We notice a sustained growth in the use of RPKI as the network operator community becomes more familiar with this technology. This helps them make informed decisions to improve their routing security.

(Free access, no subscription required)

DIFFERENCES

Every organization that has RPKI through LACNIC and uses it via the MiLACNIC platform is using hosted RPKI. In other words, LACNIC is responsible for everything related to managing cryptography, such as storing cryptographic keys, generating and storing certificates, etc. Organizations are only responsible for generating route origin authorizations (ROAs) through a web interface.

Additional reading:

On the other hand, delegated RPKI is very similar to DNS delegation. A DNS NS record, a kind of pointer, is configured in the certificate tree. All certificates corresponding to a series of numbering blocks must be retrieved from a certificate authority under the tree.

FOUNDATIONS

The LACNIC RPKI architecture comprises three layers: the RPKI core, which is the most complex part and handles all cryptographic processing; the pubserver and pre-validation layer, which validates the material that is produced, prepares the repository, and checks what will be published); and the front-end layer, which offers and publishes the validated content.

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments