Alex Band

IP Address Space Covered by Certificates

Author image
Alex Band

2 min read

0 You have liked this article 0 times.
2
Article lead image

Since the RIPE NCC launched its Resource Certification service, there is a steady increase in the number of prefixes covered by certificates.


The Resource Certification (RPKI) service was launched at the beginning of 2011. The system enables network operators to perform BGP origin validation, which means that they can securely verify if a BGP route announcement has been authorised by the legitimate holder of the address block.

 

Using their resource certificate, network operators can create cryptographically validatable statements about the route announcements they authorise to be made with the prefixes they hold. These statements are called Route Origin Authorisations (ROAs). A ROA states which Autonomous System (AS) is authorised to originate a certain IP address prefix.

 

So far, 10% of the RIPE NCC membership has opted into requesting a Resource Certificate. In the graph below, you can see the number of IPv4 prefixes (blue) and IPv6 prefixes (red) that have been certified by RIPE NCC members using their certificate. More than 900 IPv4 prefixes are certified. That means that more than 10% of the IPv4 address space the RIPE NCC is maintaining is covered by certificates. For IPv6, around 250 prefixes are certified. This is a relatively high number compared to the total number of IPv6 prefixes in the routing system.

IP Address Prefixes Covered by Certificates Figure 1: Number of IPv4 and IPv6 prefixes covered by certificates in the RIPE NCC service region

On the RIPE NCC website you can find more information about certification . You can also find more RPKI related statistics .

0 You have liked this article 0 times.
2

You may also like

View more

About the author

Author image
Alex Band Based in Amsterdam

Director of Product Development at NLnet Labs

Comments 2

The comments section is closed for articles published more than a year ago. If you'd like to inform us of any issues, please contact us.

Profile picture

Leo Vegoda

It would be useful if you would publish a plot showing the number as a percentage of the prefixes eligible for certification under the RIPE NCC's current business rules and also as a percentage of the total number of prefixes allocated or assigned by the RIPE NCC. Similarly, it would be useful to show this as a percentage of the IP address space eligible for certification under the RIPE NCC's current business rules and also as a percentage of the total address space managed by the RIPE NCC.

Profile picture

Alex Band

Thanks Leo. I will put his on my list for the beginning of next year.