Paper 2026/2233
Mind the Gap: Proving and Improving RPKI
Abstract
We present the first rigorous security analysis of the Resource Public Key Infrastructure (RPKI), an IETF standard for protecting inter-domain routing from basic yet effective attacks: prefix and subprefix hijacks. Existing evaluations of RPKI's security focus on empirical studies: adoption measurements, simulations evaluating the security provided by different adoption levels, and identification of implementation and specification flaws. In contrast, we focus on rigorous, modular security specifications and analysis of RPKI, including its interactions with the Border Gateway Protocol (BGP) and the Internet Protocol (IP). We identify sufficient conditions for RPKI to provably achieve its goals (requirements), under explicit, well-defined assumptions (models). We show that existing RPKI deployments do not always meet these conditions, e.g., because of circular dependencies, and propose standard-compliant improvements that restore them.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Resource Public Key Infrastructureprovable securityBGP
- Contact author(s)
-
shay cohen6 @ mail huji ac il
nicholas scaglione @ uconn edu
yossigi @ cs huji ac il
menahemle @ colman ac il
bing @ uconn edu
amir herzberg @ uconn edu - History
- 2026-09-28: approved
- 2026-09-27: received
- See all versions
- Short URL
- https://ia.cr/2026/2233
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2233,
author = {Shay Cohen and Nicholas Scaglione and Yossi Gilad and Hemi Leibowitz and Bing Wang and Amir Herzberg},
title = {Mind the Gap: Proving and Improving {RPKI}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2233},
year = {2026},
url = {https://eprint.iacr.org/2026/2233}
}