04-30-2014 3:47 PM
After the hack of Target, Neiman Marcus and the Heartbleed bug in OpenSSL/OpenSSh I want to know if Uverse or ATT is using the Resource Public Key Infrastructure (RPKI), also known as Resource Certification, which I read is more secure. Does anyone know much about this?
According to the Wiki entry: "
Resource Public Key Infrastructure (RPKI), also known as Resource Certification, is a specialized public
key infrastructure (PKI) framework designed to secure the Internet's routing infrastructure.
RPKI provides a way to connect Internet number resource information (such as Autonomous System numbers
and IP Addresses) to a trust anchor. The certificate structure mirrors the way in which Internet number
resources are distributed. That is, resources are initially distributed by the IANA to the Regional Internet
Registries (RIRs), who in turn distribute them to Local Internet Registries (LIRs), who then distribute the
resources to their customers. RPKI can be used by the legitimate holders of the resources to control the
operation of Internet routing protocols to prevent route hijacking and other attacks. In particular, RPKI is used
to secure the Border Gateway Protocol (BGP) through BGPSEC, as well as Neighbor Discovery Protocol
(ND) for IPv6 through the Secure Neighbor Discovery Protocol (SEND).
Work on standardizing RPKI is currently (late 2011) ongoing at the IETF in the sidr working group
(https://datatracker.ietf.org/wg/sidr/charter/), based on a threat analysis which was documented in RFC 4593.
The standards cover BGP origin validation, while work on path validation is underway.
Solved by: Go to Solution.
04-30-2014 3:51 PM
Just one question:
How much of this do you understand?
04-30-2014 4:06 PM
I'm not an Internet backbone guy. Just a concerned netizen. If this is an inappropriate question I can post it elsewhere.
04-30-2014 5:35 PM
05-01-2014 2:46 PM
05-01-2014 6:25 PM
My point in my reply earlier is that you're associating two completely distinct technologies that have nothing whatsoever to do with each other.