In such a scenario I’d argue for less automation to prevent such a rogue RIR 
from being able to cause such a disruption to the Internet. 

To expand on what Tom mentioned, Networks are not yet rejecting announcements 
with a NotFound validation. Even if such an event did occur I’d be willing to 
bet most network operators are going to be leaning on their interpersonal 
connections rather than automation to reestablish peering with networks. The 
“proof” of showing they are still allowed to announce those resources will 
happen later. In a true disaster things are going to fall back to the least 
complex solution which is simply people talking to people. 



> On Nov 13, 2024, at 09:39, Brandon Z. <bran...@huize.asia> wrote:
> 
> Hi there,
> 
> Currently, due to political factors, some countries are not particularly 
> proactive in deploying RPKI. Imagine if the RIR of a region were forced to 
> revoke all IP resources of a particular country from RPKI, effectively 
> isolating that country from the global internet.
> 
> To address this, one approach is for autonomous networks within a region to 
> establish two trusted RPKI CA servers: one from the major RIRs and another 
> locally managed. The locally managed CA would take precedence, allowing 
> autonomous networks to submit their IP resources to the RPKI server of their 
> peers (and potentially backed by a national mandate to trust this CA). This 
> setup could prevent a scenario where an entire country’s IP resources are 
> revoked, leading to all IPs being marked as invalid.
> 
> Another concept is to use blockchain technology. While cryptocurrencies use 
> computational power to verify ownership, BGP could use peer count. If an IP 
> resource is marked as valid by a majority of high-influence networks (with 
> many peers), it could be trusted by the entire internet.
> 
> Could this approach work? Perhaps there’s existing research on similar 
> methods?
> Brandon Z.
> HUIZE LTD
> www.huize.asia  <https://huize.asia/>| www.ixp.su <https://www.ixp.su/> | 
> Twitter
> 
> This e-mail and any attachments or any reproduction of this e-mail in 
> whatever manner are confidential and for the use of the addressee(s) only. 
> HUIZE LTD can’t take any liability and guarantee of the text of the email 
> message and virus.

Reply via email to