An Infrastructure to Support Secure Internet Routing
RFC 6480, “An Infrastructure to Support Secure Internet Routing”, is an Informational document published in February 2012 by M. Lepinski, S. Kent. The canonical text is published by the RFC Editor.
Abstract
This document describes an architecture for an infrastructure to support improved security of Internet routing. The foundation of this architecture is a Resource Public Key Infrastructure (RPKI) that represents the allocation hierarchy of IP address space and Autonomous System (AS) numbers; and a distributed repository system for storing and disseminating the data objects that comprise the RPKI, as well as other signed objects necessary for improved routing security. As an initial application of this architecture, the document describes how a legitimate holder of IP address space can explicitly and verifiably authorize one or more ASes to originate routes to that address space. Such verifiable authorizations could be used, for example, to more securely construct BGP route filters. This document is not an Internet Standards Track specification; it is published for informational purposes.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 6480 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6479 IPsec Anti-Replay Algorithm without Bit Shifting
- RFC 6481 A Profile for Resource Certificate Repository Structure
- RFC 6478 Pseudowire Status for Static Pseudowires
- RFC 6482 A Profile for Route Origin Authorizations
- RFC 6477 Registration of Military Message Handling System Header Fields for Use in Internet Mail
- RFC 6483 Validation of Route Origination Using the Resource Certificate Public Key Infrastructure and Route Origin Authorizations
- RFC 6476 Using Message Authentication Code Encryption in the Cryptographic Message Syntax
- RFC 6484 Certificate Policy for the Resource Public Key Infrastructure