Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

China Rolls out the ROAs

Дата публикации: 27-07-2026 09:15:00

[Editor’s Note: MANRS is republishing this article from Kentik, written by Doug Madory & Job Snijders and published on 23 July 2026. The original article is available at https://www.kentik.com/blog/china-rolls-out-the-roas/.] Summary Long a laggard in RPKI adoption, China has dramatically increased its ROA coverage from 4% to 81% since April, signaling a major commitment to securing the internet’s routing system. This […]
The post China Rolls out the ROAs appeared first on MANRS.


Основное содержимое страницы с новостью.

MANRS Guest Article

[Editor’s Note: MANRS is republishing this article from Kentik, written by Doug Madory & Job Snijders and published on 23 July 2026. The original article is available at https://www.kentik.com/blog/china-rolls-out-the-roas/.]


Summary

Long a laggard in RPKI adoption, China has dramatically increased its ROA coverage from 4% to 81% since April, signaling a major commitment to securing the internet’s routing system. This post explores the dramatic shift marking a significant milestone in global routing security, helping to protect networks from BGP routing mishaps that cause internet disruptions.


In the long-running effort to secure the internet’s routing system, RPKI Route Origin Validation (ROV) has played a central role. The success of its global adoption has been a contributing factor in reducing major disruptions caused by BGP routing mishaps.

Up until recently, the largest segment of the global internet that hadn’t yet embraced the technology was China. In this post, we’ll take a look at China’s sudden embrace of RPKI ROV by deploying Route Origin Authorizations (ROAs) for the vast majority of its BGP routes in a matter of weeks.

Background

As we’ve covered in previous posts, the deployment of RPKI ROV involves two steps: resource owners creating ROAs that define the proper origin AS of IP address space, and then networks (ASes) rejecting routes that don’t conform to those definitions. In recent years, we’ve documented the measurable progress made on both fronts.

Beginning several years ago, the majority of internet traffic is destined for RPKI-valid routes. Our analysis showed that RPKI-invalid routes rarely achieve propagation beyond a third of the internet due to the number of major ASes currently rejecting those routes. RPKI ROV works silently in the background, actively suppressing errant BGP announcements before they can cause further disruption, as evidenced by the recent leak of a BGP hijack of Telegram in India.

Here comes China

RPKI ROV deployment has been uneven at times, varying greatly from network to network and country to country. In terms of ROA coverage of routes, the Korean peninsula is divided in two halves with a counterintuitive 100% coverage in the reclusive North and nearly 0% in the hyper-advanced South. In fact, last March, a misconfiguration during North Korea’s rollout of a ROA to cover the country’s four /24 IPv4 routes led to a national outage of the country’s tiny internet.

But the big laggard in terms of national ROA creation has been China. That is, until a few weeks ago. Since April, China’s national internet registry CNNIC has been furiously publishing ROAs for the country’s major internet service providers. The result has led to a dramatic jump in ROA coverage, going from 4% to 81% according to statistics from APNIC Labs, pictured below. RIPEstat and Cloudflare Radar each provide their own views into this year’s spike in Chinese ROAs.

So dramatic was the change that the effort increased ROA coverage in the entire APNIC region (which includes most of Asia as well as Oceania) from 55% to 77% as is depicted below by the NIST RPKI Monitor site.

From a traffic standpoint, the impacts are just as profound. Kentik tags RPKI evaluation of each NetFlow upon ingestion, and when we aggregate across our dataset for traffic destined to China by RPKI evaluation, we arrive at the graphic below, which suggests a crossover point sometime last May.

Using data from the eminently helpful RPKIviews.org site, we can take a deeper look into the growth of ROAs published by CNNIC by origin between April 1 and July 20 of this year.

Under RPKI, a resource holder authorizes an ASN to originate a prefix by publishing a signed Route Origin Authorization (ROA). Relying parties — routers and validators — don’t consume ROAs directly; they flatten each one into a set of Validated ROA Payloads (VRPs), simple (prefix, ASN, maxlen) triples that get checked against BGP announcements. A single ROA object can bundle many prefixes, so it can expand into many VRPs — one ROA, thousands of VRPs.

CNNIC’s total published VRPs jumped from 2,336 to 95,535 (41x growth) over the ~3.5 months between the two snapshots — 93,685 added, 486 removed, 798 re-issued (same prefix/ASN/maxlen, new ROA hash). The growth was concentrated in a handful of massive ROAs covering large numbers of Chinese-network ASNs. Per-ASN VRP counts (old → new), sorted by growth:

NameASNApril 1, 2026July 20, 2026delta
China Mobile (Backbone)AS980810020,761+20,661
China Mobile (Jiangsu Province)AS56046115,312+5,301
China Mobile (Zhejiang Province)AS5604164,255+4,249
China Telecom (Jiangsu Province Suzhou Network)AS14029203,094+3,094
Hebei Mobile (China Mobile in Hebei Province)AS2454763,012+3,006
China TelecomAS413442,768+2,764
China Mobile Group Hunan CompanyAS5604762,423+2,417
China Unicom (Guangdong Province Network)AS1762222,321+2,319
Tencent CloudAS4509022,316+2,314
China UnicomAS4808362,277+2,241

The single biggest driver is one ROA object, which alone went from 69 VRPs (April) to 19,975 VRPs (July), apparently a mega-ROA bundling a huge number of prefix authorizations for AS9808.

Several other China Mobile/Telecom/Unicom-adjacent ASNs (56044, 4837, 4811, 24444/24445, 24400, 17623, …) show similar 100-2000x growth in the same window. The number of distinct ASNs with any CNNIC-issued VRP also grew from 290 to 806. Alongside the routable-VRP growth, CNNIC’s AS0 VRPs (which signal that a prefix is not authorized to be originated by any ASN) grew from a single entry in April to 439 by July.

Conclusion

In the years between the major routing leak of April 2010 and the Safe Host leak in 2019, China Telecom was involved in several major routing leaks contributing to the country’s reputation as the bogeyman for BGP malfeasance. However, in late 2020, China Telecom joined the MANRS effort, committing to improving its routing security practices. And since then, no major leaks involving a Chinese telecom have occurred, suggesting that many of those incidents were likely nothing more than the result of insufficient routing safeguards.

RPKI ROV seemed to be something where China was lagging. Despite the growth in adoption around the world, and especially in the APNIC region, ROA coverage for China was almost zero. But by creating ROAs covering nearly its entire internet, China moves to join much of the rest of the world in leveraging RPKI to help protect its networks from routing mishaps that can cause disruptions.

Deploying ROAs at this scale is unprecedented. It is a milestone not just for China, but for the global internet.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1RSA Conference Webinar Series Features MANRS and Routing Security012.1723-07-2026
2Updating the MANRS Network Operators Program – Latest News from the NetOpsRev Working Group06.0403-08-2026
3Welcome to a Fully Rebuilt MANRS Observatory! 06.4116-06-2026
4Latest BGP Hijack Targets Hosting Software Vendor08.9414-09-2026
5MANRS Ambassadors Are Back09.7924-08-2026
6Highlights from the First MANRS Community Meeting of 202606.924-06-2026
7Regresan los Embajadores de MANRS08.5424-08-2026
8Nominations Open for 2026 MANRS Steering Committee Elections09.6224-09-2026
9MANRS Steering Committee Elections 2026: What You Need to Know08.7317-09-2026
10Coalition for Secure AI Unveils New Agentic Identity and Security Research Following High-Profile Sessions at RSAC 2026011.3506-05-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 15.34. Источник: www.manrs.org.