This document summarizes initiatives by APNIC to promote adoption of Resource Public Key Infrastructure (RPKI) and Route Origin Authorization (ROA) in the Asia-Pacific region. It finds that some economies in Southeast Asia have over 65% ROA adoption rates, with the Philippines at 96.36%. While Malaysia has made progress, full 100% adoption has not been achieved. The document outlines APNIC's efforts like training, campaigns and interface improvements to help members create and maintain valid ROAs. It also discusses ongoing work like alerts, pre-validation and API improvements to reduce invalid routes and ROA downtimes.
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
APNIC Updates: RPKI, what we’ve learned and what we’ve been doing by Zen Chuan
1. 1
RPKI, what we’ve learned
and what we’ve been doing
MyNOG 9
Zen Chuan Ng
Senior Internet Resource Analyst
2. 2
2
Resource Public Key Infrastructure
What is RPKI?
A robust security framework for verifying the association
between resource holders and their Internet number
resources.
2
3. 3
3
Route Origin Authorization
What is contained in a ROA?
– The AS number you have authorized
– The prefix that is being originated from it
– The most specific prefix (maximum length) that the AS may
announce
For example: “ISP 4 permits AS65551 to originate a route for the prefix
198.51.100.0/24"
3
4. 4
4
RPKI initiatives
10 face-to-face and
eLearning RPKI training
courses delivered
RPKI presentations to
NOGs and conferences
Development of the
‘Ready to ROA’ campaign
– hands on sessions to
help Members create
ROAs
New shirts, stickers, web
content to promote
campaign
Ready to ROA launched in
2015
Initial challenge was to get APNIC
Members to create ROAs
21. 21
Reducing ROA downtime during transfers
• Facilitate resource transfers involving live networks
• Existing ROAs published for 2 weeks after transfers
• Avoid any down time
23. 23
23
Upcoming RPKI improvements
• Routing status alerts notification
• ROA pre-validation
• Registry API
– https://blog.apnic.net/2022/03/22/apnic-registry-api/
• New ROA guides and Help Centre articles