IETF 126 SIDROps Agenda
Chairs:
SECRETARY: Krishnaswamy Ananthamurthy (kriswamy AT cisco.com)
Tuesday Session III, July 21, 2026 - 120 Minutes
- 14:00 - 16:00 Vienna (CEST)
- 05:00 -> 07:00 PDT (San Francisco)
- 08:00 -> 10:00 EDT (New York)
- 12:00 -> 14:00 UTC
- 20:00 -> 22:00 CST (Beijing)
- 22:00 -> 00:00 AEST (Sydney)
Room: Grand Klimt Hall 2
AGENDA
0. Administration
- Speakers: Russ/Luigi/Krishna
- Agenda Bashing
- Status reports for WG drafts
- 5 Minutes (Cumulative Time: 5 Minutes)
1. ASPA Document Cluster Coordination
- Speaker: various, Job Snijders to lead discussion
2. Update on Erik Synchronisation
- Speaker: Job Snijders
- Duration: 10 minutes (Cumulative Time: 30 Minutes)
- Expected outcome: community feedback
- Abstract: Erik Synchronization is a data replication system using Merkle trees, a content-addressable naming scheme, concurrency control using monotonically increasing sequence numbers, and HTTP transport. The protocol's design is intended to be efficient, fast, easy to implement, and robust in the face of partitions or faults in the network.
- Datatracker link:
- https://datatracker.ietf.org/doc/draft-ietf-sidrops-rpki-erik-protocol/
3. IPv6 Mapping Prefix PDU for the RPKI-Router Protocol
- Speaker: Guozhen Dong
- Desired Duration: 10 minutes (Cumulative Time: 40 Minutes)
- Expected outcome: Community feedback
- Datatracker Link:
4. RPKI-based Validation with Prioritized Resource Data
- Speaker: Jia Zhang / Nan Geng
- Desired Duration: 10 minutes (Cumulative Time: 50 Minutes)
- Expected outcome: Community feedback on the updated framework and guidance on next steps
- Abstract: This draft discusses how operators may use signed RPKI data together with supplemental or locally configured routing-security data in local validation and filtering workflows. It focuses on priority-safe handling, so that supplemental data can support local routing policy without changing or silently overriding authoritative RPKI semantics. The presentation will summarize the latest updates, clarify the deployment models and operational trade-offs, and ask the working group for feedback on terminology, document scope, and next steps.
- Datatracker Link:
5. Post-Quantum Cryptography for the RPKI
- Speaker: Tomoki Yoshikawa
- Desired Duration: 10 minutes (Cumulative Time: 60 Minutes)
- Expected outcome: Community feedback on the proposed scope, algorithm selection, and migration approach.
- Abstract: This draft discusses the use of post-quantum signature algorithms in the RPKI, with ML-DSA-65 as the primary candidate. The presentation will introduce the proposal, initial evaluation results, and open migration considerations.
- Datatracker Link:
6. ASPA-based AS_PATH Verification for BGP Export
- Speaker: Jia Zhang
- Desired Duration: 10 minutes (Cumulative Time: 70 Minutes)
- Expected outcome: community feedback and whether call for WG adoption
- Abstract: This draft describes how ASPA-based AS_PATH verification can be applied at BGP export time to detect and prevent route leaks before propagation. The presentation will summarize the latest updates, explain the current procedure including neighbor-AS-augmented verification and OTC interaction, and ask the working group whether we could call for WG adoption.
- Datatracker Link:
7. Update on Autonomous System Relationship Authorization (ASRA) Drafts
- Speaker: K. Sriram
- Duration: 15 minutes (Cumulative Time: 85 Minutes)
- Expected outcome: Community feedback on the proposed ASRA drafts
- Abstract: ASRA fills in a significant gap in the ASPA method by adding the capability to detect fake links in the AS_PATHs in BGP Updates propagated from providers to customers. ASRA achieves this by allowing an AS to register additional AS relationships, i.e., customers and lateral peers. It is complementary to ASPA.
- Datatracker link:
8. Requirements for Resource Public Key Infrastructure (RPKI) Relying Parties
- Speaker: Yingying Su
- Duration: 10 minutes (Cumulative Time: 95 Minutes)
- Expected outcome: community feedback
- Abstract: This document provides a single reference point for requirements for RP software for use in RPKI. It cites requirements that appear in several RPKI RFCs and related specifications, making it easier for implementers to become aware of these requirements. This document updates RFC8897 to reflect changes to the requirements and guidance specified in the relevant RPKI standards.
- Datatracker Link:
9. Measuring propagation time of RPKI validity changes in the dataplane
- Speaker: Alexander Männel
- Desired Duration: 10 in minutes (Cumulative Time: 105 Minutes)
- Expected outcome: Providing insights, community feedback
- Abstract: We found that RPKI propagation on the dataplane is at least one order of magnitude slower than plain BGP. Invalid-to-valid transitions require 9-12 minutes, valid-to-invalid transitions need 30-42 minutes to be effective at 50% of our vantage points. Our measurements are performed from CAIDA Ark vantages points. By using the staging repository for the RIPE RPKI repository, we can perform a baseline measurement before the RPKI ecosystem reacts to potential ROA changes and track how quickly paths change by continuously performing traceroutes towards affected prefixes.
10. RPKI to router protocol over QUIC
- Speaker: Jishnu Roy
- Duration: 5 minutes (Cumulative Time: 110 Minutes)
- Expected outcome: Community feedback on the proposal
- Abstract: The Resource Public Key Infrastructure (RPKI) to Router Protocol provides a simple but reliable mechanism to receive cryptographically validated RPKI prefix origin data and router keys from a trusted cache. QUIC provides practical and secure semantics for the RTR protocol, particularly fast connection establishment and multi-stream carrying, thereby reducing the time required to complete RTR data synchronization.
- Datatracker Link:
11. Source Address Validation Using SOAs
- Speaker: Minglin Jia
- Desired Duration: 5 minutes (Cumulative Time: 115 Minutes)
- Expected outcome: community feedback
- Abstract: This update simplifies SOA by publishing only AS-level service profiles in RPKI, using them to establish channels for further SAV information exchange, thereby reducing repository storage and update-latency impacts.
- Datatracker Link:
Buffer 5 Minutes (Cumulative Time: 120 Minutes)
IF (BY ANY CHANCE) TIME ALLOWS
- Speaker: Weiqiang Cheng
- Desired Duration: 10 minutes (including Q&A)
- Expected outcome: community feedback
- Abstract:This draft analyzes RPKI/ROV deployment gaps and cross-plane information asymmetry, describes operational side effects, and frames the problem space for future work, without proposing new protocols.
- Datatracker Link:
A.2 Operational Monitoring of RPKI Repositories Health and Safety
- Speaker: Yonghong Fu
- Desired Duration: 5 minutes including Q&A
- Expected outcome: community feedback
- Abstract: This draft provides operational guidance for monitoring the health and safety of RPKI repositories on a per-publication point basis. It defines measurable indicators related to reachability, availability, and content integrity, and explains how these metrics can be used to detect degraded performance or potentially unsafe behavior.
- Datatracker Link:
A.3 A Profile for Source Prefix Authorizations (SPAs)
- Speaker: Kamiel Braet
- Desired Duration: 10 in minutes (including Q&A)
- Expected outcome: Community feedback on the proposed RPKI SPA Profile of Source-Selective BGP usage
- Abstract: This draft defines the RPKI SPA profile that enables prefix holder to authorize source prefixes for source constraint routing usage.
- Datatracker Link:
A.4 A Publication-Point-Based Incremental Validation Procedure for RPKI Relying Parties
- Speaker: Yingying Su
- Desired Duration: 10 minutes (including Q&A)
- Expected outcome: community feedback
- Abstract: This document describes a publication-point-based incremental validation procedure for RPKI RPs. The procedure is intended to reduce redundant validation work after incremental repository synchronization, while preserving the same validation result as a full top-down validation over the same repository snapshot, trust anchor set, validation policy, and validation time. This document does not change the syntax or validation semantics of any RPKI object.
- Datatracker Link:
A.5 Risk of Stealthy BGP Hijacking under Incomplete Adoption of Route Origin Validation (ROV)
- Speaker: Yi Xu
- Desired Duration: 10 minutes (Cumulative Time: 83 Minutes) 85
- Abstract: This document describes how incomplete adoption of ROV makes stealthy BGP hijacking less visible on the control plane while still capable of diverting traffic.
- Datatracker Link:
A.6 Source Pre-validation in RPKI ROV
- Speaker: Mingqing Huang
- Desired Duration: 10 minutes
- Expected outcome: community feedback
- Abstract: This document defines a BCP for source pre-validation: an originating AS checks its intended BGP announcement against its local RPKI cache before sending it to eBGP neighbors. The goal is to reduce the number of self-inflicted invalid routes, improve global routing stability, and encourage wider and more confident deployment of ROV drop policies across the Internet - including the long tail of stub and small regional ASes.
- Datatracker Link:
A.7 PAVA (PAth VAlidation): an alternative to ASPA
- Speaker: Maxence Fléchier
- Desired Duration: 10 minutes (including Q&A)
- Expected outcome: Community feedback on the proposed algorithm, focus of the work and limitations
- Abstract: This draft defines a new scheme for PATHSEC that makes use of the DNS to distribute information safely using a unique representation of AS relationships depending on the NLRI. It also describes a new verification algorithm.
- Datatracker Link:
A.8 RPKI Relying Party Benchmarking Methodology
- Speaker: Lancheng Qin
- Desired Duration: 10 minutes (including Q&A)
- Expected outcome: community feedback
- Abstract: This document defines a benchmarking methodology for evaluating RPKI Relying Party (RP) implementations in controlled laboratory environments. The methodology focuses on whether RP implementations correctly perform required validation steps and on the performance of these operations.
- Datatracker Link:
A.9 BGP Communities for Security Policy Intent
- Speaker: Yangfei Guo
- Desired Duration: 5 minutes (including Q&A)
- Expected outcome: community feedback
- Abstract: This draft defines BGP security Large Communities to convey ROV policies to downstream networks.
- Datatracker Link: