智齿有什么作用| 吃维生素c和维生素e有什么好处| 侏儒症是什么原因引起的| 甲亢有什么反应| 为什么叫新四军| 阿玛尼手表算什么档次| 寒窗是什么意思| 喝什么有助于睡眠| 521是什么星座| 珍珠状丘疹用什么药膏| 尿潴留是什么原因引起的| 什么是蓝颜知己| 排卵期身体有什么症状表现吗| 勃起功能障碍吃什么药| 前列腺炎什么症状| 纷扰是什么意思| 为什么叫水浒传| 杂酱面用什么面| 梦见辣椒是什么预兆| 饭中吃药是什么时候吃| 甲减要多吃什么食物好| 足字旁的字跟什么有关| 招财猫是什么品种| 下午6点半是什么时辰| 50年属什么生肖| 什么中不足成语| 点痣用什么方法最好| 散光是什么原因造成的| 单病种是什么意思| 脚板痛是什么原因| olay是什么牌子| 白板是什么意思| 穆斯林不吃什么| plus是什么意思| 梦见女人是什么意思| 头上戴冠是什么生肖| 房早有什么危害| 吃什么变碱性体质最快| 三人死亡属于什么事故| 氯吡格雷治什么病| 鹅蛋不能和什么一起吃| 电话停机是什么意思| 什么空如什么| 经常掉头发是什么原因| 莫名是什么意思| 腊月初七是什么星座| 做梦梦到牙齿掉了是什么意思| 热血病是什么病| 书记处书记是什么级别| 7.8什么星座| 爱新觉罗改成什么姓了| 胸围85是什么罩杯| 秦始皇是什么生肖| 吃槐花有什么好处| 中枢是什么意思| 吐气如兰是什么意思| ideal是什么意思| 细菌感染发烧吃什么药| 布洛芬0.3和0.4g有什么区别| 银行支行行长什么级别| 牛气冲天是什么生肖| 脑白质变性是什么意思| 安徒生被誉为什么| 肚脐周围疼是什么原因| 小叶紫檀有什么功效| 小孩肠套叠什么症状| 莱昂纳多为什么叫小李子| 洗手做羹汤是什么意思| 凤冈锌硒茶属于什么茶| 什么药治便秘最好最快| 肺炎吃什么消炎药| ca医学上是什么意思| 什么是法定节假日| bpo是什么| 目是什么单位| 冠心吃什么药好| 现在干什么挣钱| 六块钱的麻辣烫是什么意思| 有什么意思| 孕妇咳嗽可以吃什么药| 聚酯纤维是什么材质| 黑指甲是什么症状图片| 属猪适合佩戴什么饰品| 七月七日是什么节日| 嗓子痛吃什么药好得快| 霉菌性阴道炎什么症状| 1963年的兔是什么命| 粉饼和散粉有什么区别| 烟花三月是什么意思| 喉咙发痒吃什么药| 感冒发烧吃点什么食物比较好| 甘油三酯指的是什么| 7月1号什么节| 别人梦见我死了是什么意思| 杨树林是什么牌子| 婴儿头发长得慢是什么原因| 但愿是什么意思| 割礼是什么意思| 先天性巨结肠有什么症状| 胃窦充血水肿意味着什么| 三七粉不适合什么人吃| 浓郁是什么意思| 才美不外见的见是什么意思| ttm是什么意思| 中央候补委员是什么级别| 1992年五行属什么| 一国两制什么时候提出的| 前列腺炎需要做什么检查| 啫啫煲为什么念jue| 嘴角上扬是什么意思| 宫颈机能不全是什么意思| 什么是疝气| 什么车最长| 泰五行属什么| 隐翅虫皮炎用什么药| 4月15日什么星座| 瘘管是什么症状| 儿童看牙齿挂什么科| 什么心什么肺| 北面属于什么档次| 打榜是什么意思| 排骨焖什么好吃| 田鸡是什么| 白血病是什么症状| 裸车是什么意思| 刘备是个什么样的人| 早餐吃什么最营养| 进字五行属什么| 落地成盒什么意思| 打磨工为什么没人干| 结晶是什么意思| 64年出生属什么| 意有所指是什么意思| 1957年属什么生肖| 擤鼻涕带血是什么原因| 男性性功能下降是什么原因| 买什么保险最好最划算| 白羊女和什么星座最配| amh是什么| 奶绿是什么| 派石项链有什么功效| 国保大队是干什么的| 昂热为什么认识路鸣泽| 萎缩性胃炎吃什么药能治好| 连襟是什么意思| 谦虚的什么| 鱼皮是什么鱼的皮| 河豚为什么有毒| 栀子花什么时候开| 血管紧张素是什么意思| 灰指甲是什么原因| 被臭虫咬了擦什么药| 唯利是图是什么生肖| 自然周是什么意思| 营业执照什么时候年审| 阴道内壁是什么样的| 表面抗原阳性是什么意思| 天蝎后面是什么星座| pro是什么氨基酸| 五行代表什么意思| 充电宝100wh是什么意思| 牛刀割鸡是什么生肖| 人为什么会死亡| 手信是什么意思| 来大姨妈喝红糖水有什么作用| 流金铄石是什么意思| 扁平足适合穿什么鞋| 太阳穴长痘痘是什么原因| 6月12号是什么星座| hpv56阳性是什么意思| 坐阵是什么意思| 尿素是什么| 土豆淀粉能做什么美食| 女人喝咖啡有什么好处| 985学校是什么意思| 脑出血有什么后遗症| 颈静脉怒张见于什么病| 红绳有什么寓意| 月经前长痘痘是什么原因| 九霄云外是什么生肖| 吃秋葵有什么禁忌| 大耗是什么意思| 早上6点到7点是什么时辰| 小孩坐飞机需要什么证件| 射手座属于什么星象| b超涂的液体是什么| 尿酸高吃什么可以降下去| 住院医师是什么级别| 什么的绽放| 2.21是什么星座| 吃茶叶蛋有什么好处和坏处| 寿终正寝是什么意思| 六月属什么生肖| 红薯的别名叫什么| 牛油果对身体有什么好处| 维c什么时候吃效果最好| 舌头口腔溃疡是什么原因引起的| 汗管瘤什么原因造成| 河粉是什么| 狗哭了代表什么预兆| 0代表什么| 转氨酶偏高是什么意思| 肝功能看什么科室| 芷字五行属什么| 心火旺吃什么中药| 胃酸是什么颜色| 8月17号是什么日子| 壁虎吃什么食物| 经常放屁吃什么药| 解落三秋叶的解是什么意思| 上身胖下身瘦是什么原因| 什么是独角兽企业| 每天喝牛奶有什么好处| 前胸后背出汗多是什么原因| 欧珑香水什么档次| 外阴瘙痒用什么效果好| 女性尿路感染吃什么药好得快| 高铁上什么东西不能带| 反应性增生是什么意思| 梦见拉屎是什么意思| 北斗星代表什么生肖| 什么是面首| 脚腕酸是什么原因| 三鹿奶粉现在叫什么| 翻什么覆什么| 江西有什么好玩的地方| 弟弟的孩子叫姐姐什么| 尿道口流脓什么病| 相对湿度是什么意思| 胃有问题挂什么科| 4月7日什么星座| 咽炎吃什么药最好效果| 什么是手淫| 老鼠和什么属相最配对| 孕妇梦见别人怀孕是什么意思| 脂蛋白a是什么| 平均血小板体积偏高是什么原因| 心绞痛用什么药最好| 治疗狐臭挂什么科| 毛孔大什么原因形成的| 腰椎间盘突出是什么原因引起的| 藏红花什么时候喝最好| 小肚子疼是什么情况| 女人人中深代表什么| 肠梗阻有什么症状| 喜神是什么意思| 儿童胃肠型感冒吃什么药| 810是什么意思| 2月2日是什么星座| 什么人容易得焦虑症| 尿液带血什么原因| pmid是什么意思| 肉毒为什么怕热敷| 止血敏又叫什么名| pcr是什么| 女性适合喝什么茶| 吃榴莲有什么坏处| 海鲜不能和什么一起吃| 羊水浑浊是什么原因造成的| 6岁属什么| 特诊科是什么意思| 较重闭合性跌打损伤是什么意思| 神龙见首不见尾是什么意思| 仰卧起坐有什么好处| 百度

RPKI

RPKI

Resource certification is a security framework that proves the association between specific IP address blocks or AS numbers and the custodians of those Internet number resources (INRs). It does this through the production of public-private cryptography certificates known as PKI (for Public Key Infrastructure).

The certificates provide proof and authority to use given IPv4, IPv6 and ASN resources and can be validated cryptographically.

What is RPKI?

Resource certification uses a framework called Resource Public Key Infrastructure (RPKI), which is based on X.509 PKI certificate standards. Using a validation structure called RPKI, resource holders can confidently state that the information being transmitted is correct and corresponds to their intentions.

RPKI allows network operators to digitally encrypt and sign routing advertisements in Border Gateway Protocol (BGP) by using a system of private and public keys. Information can be encrypted and signed with a private key and can only be decrypted, or have its signature verified, using the matching public key. Digitally signing information provides assurance that routing advertisements seen in the routing system can be verified and are authentic.

RPKI works by adding INR information to X.509 PKI certificates issued to resource holders. This represents custodianship and other status information regarding a particular INR. When RPKI certificates are used, the INRs are associated with the digital signature. Proving the signature can, therefore, attest the INRs relate to what has been signed. You cannot sign correctly referring to INRs that are not contained in your certificate.

RPKI works by forming hierarchies of certificates signing over each other. A ‘root’ certificate signs over child certificates, which sign over their child certificates and so on. The act of signing a certificate makes you a certificate authority or CA. RPKI assigns CA status to the agencies that delegate INRs, so the delegation role aligns with the CA role. Regional Internet Registries (RIR) sign certificates for direct Members and for National Internet Registries (NIRs), both of whom may sign certificates and other RPKI products regarding the resources in their certificates.

In addition to certificates signing other certificates (the CA role), certificates can be used to sign other digital objects. This is called an end-entity or EE certificate: it does not sign other CA certificates, it only signs non-certificate objects. In RPKI, EE certificates are used to sign manifests (catalogues of signed objects) and to sign routing and other digital objects. The primary signed object in routing is the Route Origin Authorization or ROA.

RPKI applications

These are two current applications of RPKI:

Benefits of RPKI

  • Much safer than manually checking the APNIC Whois Database or the IRR database.
  • Secure origin of the prefix or origin-as is the first step to preventing many attacks on BGP integrity.
  • Instruction/information from the resource custodian can be cryptographically verified (for example, Letter of Authority signing).

APNIC’s RPKI

RPKIs publish all their products in a repository. All PKIs depend on a trust anchor. This is typically fetched as a self-signed certificate but actually is defined by the key. You MUST fetch your trust anchor independently of any other PKI products you will be validating.

APNIC’s RPKI repository includes a single ‘all resources’ certificate as a self-signed trust anchor. Underneath this trust anchor, APNIC has five sub-repositories with distinct subsets of the INRs it manages. This reflects those resources for which administrative responsibility has been assigned to APNIC directly by IANA as described in the IANA registries, and those resources whose administrative role has been transferred to APNIC from each of the other four RIRs.

See APNIC’s RPKI Trust Anchor Locator

Find out how APNIC has implemented RPKI

Find out how APNIC has implemented a Single Trust Anchor

Certificate management services

APNIC resource holders can create and manage their resource certificates and associated objects (for example, ROAs) via MyAPNIC. The service embedded in MyAPNIC is a child CA specific to the resource holder, operated on their behalf inside APNIC services but run distinctly from the APNIC CA, which is bound to the registry. APNIC holds your private keys, and at all times the products you sign are your products, signed with your keys.

Alternatively, resource holders can operate their own locally managed RPKI system and communicate with the APNIC RPKI using the standard ‘RPKI Provisioning Protocol’ RFC 6492. This is typically only relevant to resource holders who need to automate/script their RPKI operations. This model is also used by the NIR to provide services hosted in their economy, for their direct membership. This form of operation is often called “self hosted”. It is possible to run both MyAPNIC and self-hosted RPKI, for transition purposes. Currently, subscription to self-hosted RPKI along with MyAPNIC hosted services requires manual intervention. Contact helpdesk@apnic.net for assistance.

ROV and ROA

BGP route assertions have an origin AS and a series of AS forming the path. Route Origin Validation (ROV) is the application of RPKI to validating the origin AS.

The main and most widely known application of RPKI is Route Origin Validation (ROV).

  • ROV is performed using a Route Origin Authorization (ROA). A ROA lists the prefixes that an ASN is authorized to announced. ROAs therefore state which AS is authorized to originate certain IP address prefixes. Once validated, a ROA can be used to generate route filters.

Benefits of creating a ROA

  • Verify whether an AS is authorized to announce a specific IP prefix
  • Minimize common routing errors
  • Prevent most accidental hijacks

What’s contained in a ROA

  • The AS number you authorize
  • The prefix that is being originated from it
  • The most specific prefix (maximum length) that the AS may announce

A ROA might look like this for example,

“ISP 4 permits AS 65000 to originate a route for the prefix 192.2.200.0/24”

Create your ROA in MyAPNIC

It’s easy to create a ROA. Log in to your MyAPNIC account and follow the step-by-step guide.

Resource Tagged Attestation

Another potential application of RPKI is Resource Tagged Attestation (RTA), which allows RPKI certificates to be used to sign an arbitrary object, such as a cryptographic verifiable ‘Letter of Authority’ (LOA) as a PDF file, or word document.

Current practice uses an informal scanned/signed PDF under company letterhead, which is unverifiable without more information. Forging a LOA is a risk that cannot easily be detected as-is.

RTA generates a ‘detached signature’ using RPKI. The signing certificate contains the IP address range listed in the LOA document. The signed object contains the specific IP resources relevant to the signing, identifies the certificate that proves the resource holder has control, and a digital signature of the object being signed. This is now a cryptographically verifiable object (for instance a LOA) and can be automated.

The exact intent of the resources included is not specified: it depends entirely on the meaning of the signed object. So, a LOA should continue to state conclusively which INRs it relates to.

APNIC is developing RTA and will release services in due course.

Trust Anchor Locator

APNIC operates the RPKI system under a single trust anchor. This has been chosen to cover ‘all resources’ across IPv4, IPv6 and ASNs in line with a decision made by the NRO.

The single trust anchor is represented by a file called a ‘Trust Anchor Locator’ or TAL. It is very important that relying parties, who consume the products of the APNIC RPKI system have this TAL configured into their validator.

The current APNIC TAL as of YYYY-MM-DD is shown below, in two formats:

1. RIPE NCC Validator format:


ca.name = APNIC RPKI Root
certificate.location = rsync://rpki.apnic.net/repository/apnic-rpki-root-iana-origin.cer
public.key.info = MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx9RWSL61YAAYumEiU8z8qH2ETV
IL01ilxZlzIL9JYSORMN5Cmtf8V2JblIealSqgOTGjvSjEsiV73s67zYQI7C/iSOb96uf3/s86NqbxDiFQGN8qG7
RNcdgVuUlAidl8WxvLNI8VhqbAB5uSg/MrLeSOvXRja041VptAxIhcGzDMvlAJRwkrYK/Mo8P4E2rSQgwqCgae0e
bY1CsJ3Cjfi67C1nw7oXqJJovvXJ4apGmEv8az23OLC6Ki54Ul/E6xk227BFttqFV3YMtKx42HcCcDVZZy01n7Jj
zvO8ccaXmHIgR7utnqhBRNNq5Xc5ZhbkrUsNtiJmrZzVlgU6Ou0wIDAQAB
prefetch.uris = rsync://rpki.apnic.net/member_repository/

2. Routinator and RPKI.Net format:

 
rsync://rpki.apnic.net/repository/apnic-rpki-root-iana-origin.cer

MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx9RWSL61YAAYumEiU8z8
qH2ETVIL01ilxZlzIL9JYSORMN5Cmtf8V2JblIealSqgOTGjvSjEsiV73s67zYQI
7C/iSOb96uf3/s86NqbxDiFQGN8qG7RNcdgVuUlAidl8WxvLNI8VhqbAB5uSg/Mr
LeSOvXRja041VptAxIhcGzDMvlAJRwkrYK/Mo8P4E2rSQgwqCgae0ebY1CsJ3Cjf
i67C1nw7oXqJJovvXJ4apGmEv8az23OLC6Ki54Ul/E6xk227BFttqFV3YMtKx42H
cCcDVZZy01n7JjzvO8ccaXmHIgR7utnqhBRNNq5Xc5ZhbkrUsNtiJmrZzVlgU6Ou
0wIDAQAB

One of these two formats should be used to write the TAL as a configured element of your validator.

Should APNIC change the TAL, this will be communicated widely, and software should update. The TAL can always be verified by referring to these web pages.

Under this single TAL, APNIC operates a number of subsidiary RPKI CAs to represent the states of Internet number resources we receive from IANA directly, and from other RIRs via transfers. This logistical separation means we can clearly identify transfers in from resources delegated down.

Previously, APNIC operated five distinct TALs, one for each of these cases (the four other RIRs and IANA). A transition plan was enacted which completed in February 2018 and is documented on the Single Trust Anchor transition webpage.

Additional TAL for AS0

The Implementation of Prop132 (AS0 ROA for bogons) necessitates the use of an additional TAL, because we operate this service discretely, separated from the main service TAL.

3. AS0 TAL in RIPE NCC Validator format:


ca.name = APNIC AS0 Root
certificate.location = rsync://registry-testbed.apnic.net/as0-test/ta/ta.cer
public.key.info = MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvo8wLXUFnUjXyX
hy11VpFWiDZy7Hs9TAIfymiKwCbOz3ZMp8iWgWoxI5IJzO0cIz/KaRgBbzVeXRFttp3nzh5Up+EQ
XnL3ixWh3gAjSD0mTOLchLtS4pSuuHxLfdqTreCRLVK2Fbq09jUUPf76C6TazIQouMp6epGOJZvS
fmBMK3TQphlXC/iREbiMtDL7gPhexidllhuNbk4PXXBhXxoUjOEG4YdVUC/MV3dXZ72IOtl1HQ9J
3tky/bgaDVykD4j4wqHyrzhiXQ45KIrY7JGT95Z++L00OrjxlLwZoKi5vxh9U4rDtNUhPKESzpqu
t1+cO4WX+Z6L2DR80abh1DOQIDAQAB

4. AS0 TAL in Routinator and RPKI.net format:


rsync://registry-testbed.apnic.net/as0-test/ta/ta.cer
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvo8wLXUFnUjXyXhy11VpFWiDZy7Hs9TA
IfymiKwCbOz3ZMp8iWgWoxI5IJzO0cIz/KaRgBbzVeXRFttp3nzh5Up+EQXnL3ixWh3gAjSD0mTO
LchLtS4pSuuHxLfdqTreCRLVK2Fbq09jUUPf76C6TazIQouMp6epGOJZvSfmBMK3TQphlXC/iREb
iMtDL7gPhexidllhuNbk4PXXBhXxoUjOEG4YdVUC/MV3dXZ72IOtl1HQ9J3tky/bgaDVykD4j4wq
HyrzhiXQ45KIrY7JGT95Z++L00OrjxlLwZoKi5vxh9U4rDtNUhPKESzpqut1+cO4WX+Z6L2DR80a
bh1DOQIDAQAB
莲藕炒什么好吃 坨是什么意思 祭是什么意思 被毒蛇咬了有什么症状 口干口苦什么原因
亦或是什么意思 为什么喝中药越来越胖 木加号读什么 什么是无精症 强盗是什么意思
什么时间吃水果最好 施华洛世奇水晶是什么材质 细菌性感冒吃什么药效果好 尿是褐色的是什么原因 什么样的土豆不能吃
眷顾是什么意思 针清是什么 脚转筋是什么原因引起的 去香港需要准备什么 什么东东
办护照带什么资料hcv7jop6ns3r.cn 吃人肉会得什么病hcv8jop3ns3r.cn 舌钉有什么用tiangongnft.com 蛇鼠一窝是什么意思hcv7jop9ns0r.cn 种植什么最赚钱农村hcv9jop1ns9r.cn
升米恩斗米仇什么意思hcv8jop4ns8r.cn 菠菜和什么不能一起吃hcv8jop2ns9r.cn 宝宝老是摇头是什么原因hcv7jop4ns6r.cn 白细胞十一是什么意思cl108k.com tel是什么意思啊hcv9jop5ns6r.cn
高碱性食物都有什么hcv7jop9ns8r.cn 什么什么二什么成语zhongyiyatai.com 三七主要治什么病hcv8jop3ns4r.cn 血压低什么原因造成的hcv8jop3ns6r.cn 不能吃油腻的是什么病gysmod.com
白带黄色是什么原因hcv9jop4ns9r.cn 什么是碳足迹1949doufunao.com 炎症吃什么消炎药hcv8jop6ns5r.cn 什么颜色加什么颜色等于灰色hcv9jop6ns6r.cn 暗房是什么意思hcv9jop0ns2r.cn
百度