Out-of-Band Path Validation to Mitigate Inter-AS Routing Exploits
draft-voet-bgp-oob-validation-00
This document is an Internet-Draft (I-D).
Anyone may submit an I-D to the IETF.
This I-D is not endorsed by the IETF and has no formal standing in the
IETF standards process.
| Document | Type | Active Internet-Draft (individual) | |
|---|---|---|---|
| Author | Gunther Voet | ||
| Last updated | 2026-06-18 | ||
| RFC stream | (None) | ||
| Intended RFC status | (None) | ||
| Formats | |||
| Stream | Stream state | (No stream defined) | |
| Consensus boilerplate | Unknown | ||
| RFC Editor Note | (None) | ||
| IESG | IESG state | I-D Exists | |
| Telechat date | (None) | ||
| Responsible AD | (None) | ||
| Send notices to | (None) |
draft-voet-bgp-oob-validation-00
Network Working Group Gunther Voet
Internet-Draft Independent Researcher
Intended status: Informational June 18, 2026
Expires: December 20, 2026
Out-of-Band Path Validation to Mitigate Inter-AS Routing Exploits
draft-voet-bgp-oob-validation-00
Abstract
This document describes a mechanism for mitigating Inter-AS routing
exploits and path tampering without introducing real-time cryptographic
processing overhead on core routing engines. By utilizing Out-of-Band
(OOB) Cryptographic Validation combined with localized caches via the
RPKI-to-Router (RTR) protocol and Autonomous System Provider
Authorization (ASPA), networks can asynchronously verify path
plausibility. This architecture supports incremental, partial
deployment to protect infrastructure against malicious traffic redirection
and unauthorized path propagation at major internet exchange points.
Status of This Memo
This Internet-Draft is submitted in full conformance with the
provisions of BCP 78 and BCP 79.
Internet-Drafts are working documents of the Internet Engineering Task
Force (IETF), its areas, and its working groups. Note that other
groups may also distribute working documents as Internet-Drafts.
Internet-Drafts are draft documents valid for a maximum of six months
and may be updated, replaced, or obsoleted by other documents at
any time. It is inappropriate to use Internet-Drafts as
reference material or to cite them other than as "work in
progress."
The list of current Internet-Drafts can be accessed at
https://www.ietf.org/1id-abstracts.html
The list of Internet-Draft Shadow Directories can be accessed at
https://www.ietf.org/shadow.html
This Internet-Draft will expire on December 20, 2026.
Copyright Notice
Copyright (c) 2026 IETF Trust and the persons identified as the
document authors. All rights reserved.
This document is subject to BCP 78 and the IETF Trust's Legal Provisions
Relating to IETF Documents
(https://trustee.ietf.org/license-info) in effect on the date of
publication of this document. Please review these documents
carefully, as they describe your rights and restrictions with
respect to this document.
1. Introduction
The global routing system relies on the Border Gateway Protocol (BGP),
which is inherently vulnerable to route hijacking and path manipulation.
While Resource Public Key Infrastructure (RPKI) provides Route Origin
Validation (ROV), it lacks the ability to validate path integrity.
Malicious actors can bypass origin filters by forging an unauthorized
transit path (AS_PATH) while retaining a legitimate origin AS at the
end of the chain. These manipulated paths propagate through large
interconnection hubs, such as the Amsterdam Internet Exchange (AMS-IX),
enabling cross-border infrastructure manipulation and digital harassment.
Previous attempts to secure the path layer (e.g., S-BGP) failed due to
the massive CPU overhead required for real-time cryptographic signing
on core routers. This document outlines an upgradable, backward-compatible
solution utilizing localized, asynchronous validation to achieve
path security with zero additional router CPU cycles.
2. Protocol Overview & Out-of-Band Logic
To eliminate processing overhead on live forwarding planes, validation
is decoupled from standard routing updates using an asynchronous model:
2.1. Local Cache Injection
Instead of forcing core routers to execute real-time cryptographic
signature checks on every incoming route advertisement, routers
connect locally to an out-of-band validator using the RTR protocol.
The validator pre-computes and signs the valid cryptographic ledger.
2.2. Asynchronous Ledger Validation
Validation occurs out-of-band using specialized RPKI validating
caches (e.g., Routinator). Routers download verified public key
ledgers asynchronously in the background. This allows routers to
instantly filter or block unauthenticated, spoofed paths using a
local memory lookup table without degrading traffic throughput.
2.3. Incremental Partial Deployment
This architecture allows for seamless partial deployment. Individual
networks can implement these validation caches independently to
protect their users immediately, without requiring a coordinated,
simultaneous upgrade across all global transit networks.
3. Autonomous System Provider Authorization (ASPA)
Alongside local cache validation, networks deploy ASPA to combat path
spoofing. ASPA utilizes cryptographically signed objects in the RPKI
to define authorized provider lists for an AS. Routers use these
lightweight, pre-computed profiles to verify path plausibility and
automatically flag unauthorized route leaks before they propagate.
4. Security Considerations
This document addresses the exploitation of standard BGP implicit trust.
By shifting cryptographic computation to an out-of-band local cache,
this mechanism prevents denial-of-service conditions on core routers
caused by high-volume malicious routing updates. It specifically blocks
unauthorized transit path injection used for traffic interception.
5. IANA Considerations
This document has no actions for IANA.
6. References
[RFC8210] Bush, R. and R. Austein, "The Resource Public Key
Infrastructure (RPKI) to Router Protocol, Version 1",
RFC 8210, September 2017.
[ASPA] RIPE NCC Documentation, "ASPA and Path Validation Overview".
Author's Address
Gunther Voet
Independent Internet Security Researcher / Administrator
Email: bgp-draft@xsrv.net