10/02/2026 | Press release | Distributed by Public on 10/01/2026 17:35
RPKI has become the Internet's primary defence against Border Gateway Protocol (BGP) route hijacks. By allowing network operators to cryptographically authorize Autonomous Systems (ASes) that may originate specific IP prefixes, RPKI helps prevent a wide range of accidental leaks, misconfigurations, and some malicious route hijacking attacks.
Each time a Route Origin Authorization (ROA) is created, modified, revoked, or expires, routers performing Route Origin Validation (ROV) may need to reconsider routing decisions. Those decisions can then propagate through BGP, generating additional BGP updates. In other words, RPKI introduces a new class of events that can potentially trigger routing changes across the Internet.
This raises the following concern: Could the growing deployment of RPKI become a threat to routing stability? To answer that question, we analysed more than 11 years of RPKI and BGP data, measuring how much routing activity can be associated with RPKI-related changes.
RPKI is growing fast
To understand the relevance of our question on the impact of RPKI on routing, it is worth looking at how much the RPKI ecosystem has changed over time.
Figure 1 shows the evolution of RPKI changes observed between 2014 and 2025. The number of ROA creations, expirations, and revocations has increased significantly over the years for both IPv4 and IPv6.
This trend reflects the steady adoption of RPKI by network operators and the increasing amount of address space protected through ROAs. Regulatory initiatives and industry best practices are further accelerating this deployment.
The implication is straightforward: If each RPKI change has the potential to trigger routing updates, then a rapidly growing number of RPKI changes could translate into a rapidly growing amount of BGP activity.
The motivation behind our study is understanding whether this BGP activity remains negligible or becomes operationally significant.
Building an 11-year RPKI time machine
Measuring the impact of RPKI on BGP is more challenging than it may initially appear.
The first challenge is identifying the moments when RPKI can actually influence routing. A ROA creation or revocation does not automatically correspond to a routing change. What matters is whether the set of authorizations seen by routers changes. We refer to these moments as RPKI events. An RPKI event occurs whenever a validated authorization (VRP) becomes available or disappears, potentially changing the validation state, impacting the routing decisions, and thus triggering one or more BGP announcements.
The second challenge is historical visibility. While it is possible to observe recent RPKI activity in detail, obtaining a comparable view over more than a decade requires reconstructing events from archival data.
To address these challenges, we developed a methodology that combines historical RPKI information with BGP update measurements.
Our methodology built an 11-year 'time machine' that allows us to track how the routing impact of RPKI evolved, from the early days of deployment to today.
RIPE Archive and Flutter data
The study relies on two complementary RPKI data sources.
Figure 2 compares the number of RPKI-related BGP updates identified using Archive-derived events and Flutter-observed events during the period where both datasets overlap.
The resulting update volumes are remarkably similar. This observation suggests that the Archive-based methodology provides a reliable estimate of historical RPKI-induced routing activity, allowing us to extend the analysis far beyond the period covered by Flutter.
RPKI is not a harmful source of BGP noise
The main result of the paper is summarized in Figure 3.
The figures show the fraction of all observed BGP updates that can be associated with RPKI events over time. While this fraction is clearly increasing, it remains extremely small when compared with the overall volume of BGP activity.
Even adopting methodologies that tend to overestimate the number of RPKI-induced updates, the observed contribution remains well below 1% of the total BGP update volume.
On the other hand, the data reveals a clear upward trend. As more address space becomes protected by RPKI and more networks deploy ROV, the amount of RPKI-related routing activity also increases. The growth is visible in both the Archive-based historical data and the more recent Flutter measurements.
The important point is that, while the trend is increasing, the absolute contribution remains very small.
What should you worry about?
From an operational perspective, the results are reassuring.
First, the study provides strong evidence that RPKI is not currently a significant source of BGP noise. Even though RPKI events can lead to routing updates, the resulting volume is negligible.
Second, the findings suggest that operators should not view routing stability as a major obstacle to RPKI deployment. Assuming that ROAs are managed correctly and operational best practices are followed, the additional routing overhead introduced by RPKI appears to be very small.
However, the story is not over. The growth in RPKI-related updates closely follows the growth of RPKI deployment itself, and the observed trend in both is increasing. As ROV becomes more widely deployed, the operational impact of RPKI may continue to evolve. For that reason, continued monitoring remains important. The good news is that after examining more than eleven years of measurements, we can conclude that RPKI's security benefits are currently achieved with a remarkably small impact on routing stability.
Readers interested in the methodology, datasets, and detailed analyses can find the complete results in our paper.
Samuele is a PhD Student at Roma3 University. His research focuses on several aspects of interdomain routing, particularly on the detection and analysis of routing instabilities, the inference of AS-level policies and relationships, and the analysis and measurement of routing events related to the impact of RPKI on routing stability.
The views expressed by the authors of this blog are their own and do not necessarily reflect the views of APNIC. Please note a Code of Conduct applies to this blog.