Skip to content
INTERNET INFRASTRUCTURE & NETWORKS

Eleven-Year Study Finds RPKI Expansion Does Not Threaten BGP Stability

The Resource Public Key Infrastructure (RPKI) has firmly established itself as the internet’s primary defense against malicious or accidental Border Gateway Protocol (BGP) route hijacks. By allowing network operators to cryptographically authorize specific Autonomous Systems (ASes) to originate designated IP prefixes, RPKI helps safeguard global routing infrastructure from a wide range of configuration errors, accidental leaks, and targeted attacks.

However, as the adoption of RPKI accelerates worldwide, network engineers have long pondered a critical operational question: Does the continuous stream of RPKI modifications introduce harmful instability into the global routing system?

To answer this pressing question, researchers recently analyzed more than eleven years of historical RPKI and BGP data to measure exactly how much routing activity can be directly attributed to RPKI-related changes. The findings offer reassurance to the global networking community, revealing that while RPKI-induced BGP activity is growing in tandem with ecosystem adoption, it remains an extremely small fraction of total internet routing noise and poses no immediate threat to routing stability.

RPKI is Growing Fast Across the Global Internet

To contextualize the debate surrounding routing stability, it is necessary to examine how rapidly the RPKI ecosystem has evolved over the past decade. Between 2014 and 2025, the volume of Route Origin Authorization (ROA) creations, expirations, and revocations has surged dramatically across both IPv4 and IPv6 address spaces.

This exponential upward trajectory reflects a broader industry movement toward enhanced internet security. Driven by collective regulatory initiatives, heightened security awareness, and established industry best practices, network operators around the globe are increasingly implementing Route Origin Validation (ROV) and protecting their address space with ROAs.

Is RPKI becoming harmful to BGP stability? | APNIC Blog

Yet, this operational reality brings underlying mechanics into focus. Every time a ROA is created, modified, revoked, or allowed to expire, routers performing ROV may need to reconsider their path selection and routing decisions. Those decisions subsequently propagate through the global BGP mesh, generating additional routing updates. Consequently, RPKI introduces an entirely new class of cryptographic events capable of triggering routing changes across the internet.

The core motivation behind the eleven-year study was to determine whether this growing volume of generated BGP activity remains negligible in practice or whether it is evolving into an operationally significant source of routing volatility.

Building an 11-Year RPKI Time Machine

Measuring the precise correlation between RPKI modifications and BGP fluctuations is considerably more complex than it might initially appear to outside observers. Researchers faced two major methodological hurdles when attempting to construct a comprehensive evaluation framework.

The first major challenge involved identifying the exact moments when RPKI changes can actually influence active routing paths. A simple ROA creation or revocation does not automatically translate into an immediate routing change. The crucial factor is whether the set of validated authorizations seen by routers actually shifts—a milestone the researchers define as an RPKI event. Such an event occurs whenever a validated route payload becomes available or disappears, potentially altering validation states, shifting routing decisions, and ultimately triggering one or more BGP announcements.

The second major hurdle was historical visibility. While obtaining granular, real-time data on recent RPKI operations is relatively straightforward today, securing a comparable, high-fidelity view spanning more than a decade required reconstructing historical events from complex archival sources.

Is RPKI becoming harmful to BGP stability? | APNIC Blog

To overcome these obstacles, the research team developed an advanced methodology that effectively built an eleven-year analytical time machine. This framework made it possible to track the evolution of RPKI’s routing impact from its early, experimental deployment phases all the way to its current widespread integration.

Leveraging RIPE Archive and Flutter Data for Long-Term Analysis

The robust study relied on two complementary, high-resolution RPKI data sources to ensure accuracy across the lengthy timeline. By correlating historical archives with modern observation tools, the researchers were able to cross-validate their findings against real-world network telemetry.

When researchers compared the volume of RPKI-related BGP updates identified through historical archive-derived events with those observed through real-time Flutter events during an overlapping period from May 2024 to August 2025, the results aligned remarkably well. For both IPv4 and IPv6 traffic, the resulting update volumes tracked each other closely.

This strong correlation demonstrated that the archive-based methodology provides a reliable and accurate estimate of historical RPKI-induced routing activity. Crucially, it validated the extension of the analysis far beyond the temporal boundaries of modern monitoring tools, creating a dependable window into the past behavior of interdomain routing.

RPKI is Not a Harmful Source of BGP Noise

The primary conclusion of the extensive study centers on the proportional volume of routing updates generated by cryptographic validation changes. While the fraction of observed BGP updates associated with RPKI events has steadily increased over the years, it remains exceptionally small when contrasted against the massive, continuous background noise of total global BGP activity.

Is RPKI becoming harmful to BGP stability? | APNIC Blog

Even when applying rigorous methodologies intentionally designed to overestimate the number of RPKI-induced updates, the observed contribution of these events remains well below 1 percent of total BGP update volume.

At the same time, the data undeniably reveals a clear, steady upward trend. As more internet address space falls under cryptographic protection and an increasing number of autonomous systems deploy route origin validation, the absolute amount of RPKI-related routing activity naturally rises. This growth is consistently visible in both long-term historical archives and contemporary measurements.

The vital takeaway, however, is that despite this upward trajectory, the absolute contribution to overall network traffic remains remarkably minor.

Operational Takeaways and What Network Engineers Should Focus On

From a practical, day-to-day operational perspective, the research findings offer deeply reassuring news for network architects and system administrators.

First, the study provides robust empirical evidence that RPKI is not currently acting as a significant or harmful source of BGP noise. Although individual RPKI events can and do result in localized routing updates, the aggregate volume produced across the global internet is negligible.

Is RPKI becoming harmful to BGP stability? | APNIC Blog

Second, the findings strongly suggest that concerns surrounding routing stability should not be viewed as a valid obstacle to broader RPKI deployment. Provided that network operators manage their ROAs correctly and adhere to established operational best practices—such as avoiding overly broad prefix authorizations and monitoring expiration dates—the extra routing overhead introduced by RPKI validation is minimal.

Nevertheless, the story of interdomain routing is continuously evolving. The steady upward trend in RPKI-related updates directly mirrors the broader adoption curve of the technology itself. As Route Origin Validation becomes an even more ubiquitous baseline standard across global transit providers, the operational footprint of RPKI will continue to mature.

For this reason, ongoing network monitoring remains an essential component of operational hygiene. Ultimately, after examining more than a decade of empirical measurements, the research confirms that the substantial security benefits of RPKI against route hijacking are currently being achieved with a remarkably minor footprint on overall global routing stability.

The complete research methodology, comprehensive datasets, and detailed technical analyses are published in the academic paper available through the Association for Computing Machinery.

Samuele is a PhD student at Roma3 University whose research centers on interdomain routing, the detection and analysis of routing instabilities, the inference of AS-level policies and relationships, and the measurement of routing events related to the impact of RPKI on network stability.

Leave a Reply

Your email address will not be published. Required fields are marked *