Welcome to Mitigating BGP Hijacking with RPKI and Route Origin Validation. The Border Gateway Protocol (BGP) is the routing protocol of the internet, but it was designed with an inherent flaw: implicit trust. Historically, any Autonomous System (AS) could advertise routing paths for IP prefixes it did not own, leading to traffic interception or blackholingβ€”known as BGP hijacking.

1. The Mechanics of a Route Hijack

A BGP hijack occurs when an AS announces a route to an IP block (e.g., `203.0.113.0/24`) that it is not authorized to originate. Because BGP routers prefer more specific prefixes (like a /24 over a /23) or shorter AS paths, malicious or accidental announcements can rapidly propagate globally, causing massive internet outages or silent traffic rerouting.

2. Introducing RPKI

Resource Public Key Infrastructure (RPKI) brings cryptographic verification to BGP routing. In the RPKI framework, Regional Internet Registries (RIRs like ARIN, RIPE, APNIC) issue X.509 certificates that tie IP address blocks and AS Numbers to a public key. Network operators use these certificates to create Route Origin Authorizations (ROAs), cryptographically stating, "AS 65530 is authorized to originate route 203.0.113.0/24."

3. Implementing Route Origin Validation (ROV)

Creating ROAs is only half the battle; networks must enforce them. Route Origin Validation (ROV) is the process where a router checks incoming BGP announcements against a local cache of cryptographic ROAs (using the RTR protocol). Routes are assigned states: Valid, NotFound, or Invalid.

4. Dropping Invalid Routes

The crucial security step for major ISPs and tier-1 carriers is configuring their edge routers to actively drop Invalid routes. If a router receives a BGP announcement for a prefix that conflicts with the cryptographic ROA (e.g., wrong originating ASN or a prefix length longer than the ROA allows), the router discards the route, neutralizing the hijack before it can propagate further into the network.

Conclusion

RPKI and Route Origin Validation are the definitive cures for BGP hijacking. As global ROA creation and enforcement adoption reach critical mass, the internet's routing fabric shifts from a model of implicit trust to verifiable cryptographic security.