<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.kent-sidr-suspenders" target="https://datatracker.ietf.org/doc/html/draft-kent-sidr-suspenders-04">
   <front>
      <title>Suspenders: A Fail-safe Mechanism for the RPKI</title>
      <author initials="S." surname="Kent" fullname="Stephen Kent">
         <organization>BBN Technologies</organization>
      </author>
      <author initials="D." surname="Mandelberg" fullname="David Mandelberg">
         <organization>BBN Technologies</organization>
      </author>
      <date month="October" day="19" year="2015" />
      <abstract>
	 <t>   The Resource Public Key Infrastructure (RPKI) is an authorization
   infrastructure that allows the holder of Internet Number Resources
   (INRs) to make verifiable statements about those resources.  The
   certification authorities (CAs) in the RPKI issue certificates to
   match their allocation of INRs.  These entities are trusted to issue
   certificates that accurately reflect the allocation state of
   resources as per their databases.  However, there is some risk that a
   CA will make inappropriate changes to the RPKI, either accidentally
   or deliberately (e.g., as a result of some form of &quot;government
   mandate&quot;).  The mechanisms described below, and referred to as
   &quot;Suspenders&quot; are intended to address this risk.

   Suspenders enables an INR holder to publish information about changes
   to objects it signs and publishes in the RPKI repository system.
   This information is made available via a file that is external to the
   RPKI repository, so that Relying Parties (RPs) can detect erroneous
   or malicious changes related to these objects.  RPs can then decide,
   individually, whether to accept changes that are not corroborated by
   independent assertions by INR holders, or to revert to previously
   verified RPKI data.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-kent-sidr-suspenders-04" />
   
</reference>
