May 2026 CACM: Are We Actually There? Assessing RPKI Maturity

ACM (Association for Computing Machinery)
ACM (Association for Computing Machinery)Apr 24, 2026

Why It Matters

RPKI’s partial deployment already shields much of the internet, yet hidden flaws could expose critical routing infrastructure, making coordinated research and standards upgrades essential for true resilience.

Key Takeaways

  • RPKI secures over half of BGP prefixes but still immature
  • Deployment complexity increases error risk and misconfiguration possibilities
  • Software bugs, like Amazon object rejection, expose unprotected routes
  • Patch delays and open‑source quality issues leave many RPKI nodes vulnerable
  • Coordinated standards, research, and operator guidance needed for true maturity

Summary

The May 2026 Communications of the ACM paper "Are We Actually There? Assessing RPKI Maturity" examines whether the Resource Public Key Infrastructure (RPKI) has reached the maturity level touted by the White House in 2024. While RPKI now protects more than 50% of BGP prefixes, the authors argue that its operational reliability remains incomplete.

Through simulations and field measurements, the researchers found that broader deployment makes the routing ecosystem more intricate, increasing the likelihood of configuration errors and exploitable software bugs. Notable issues include an Amazon‑issued object that validators misinterpreted, leaving those prefixes unprotected, and widespread delays in patching open‑source RPKI implementations, some of which may contain hidden vulnerabilities.

The paper highlights concrete examples: the Amazon organization‑name field error, inconsistent validator behavior across vendors, and the absence of a robust certification process for RPKI components. The authors call for more published operational experiences to give network operators a clear deployment roadmap and stress that the current specification lacks flexibility for future cryptographic algorithms.

The authors conclude that RPKI is a valuable security layer but requires coordinated effort among standards bodies, researchers, and operators to address software quality, patch management, and specification agility. Without such collaboration, the perceived maturity may mask systemic risks that could undermine internet routing security.

Original Description

Haya Schulmann, Niklas Vogel, and Michael Waidner discuss "Are We Actually There? Assessing RPKI Maturity," a Research Article in the May 2026 CACM

Comments

Want to join the conversation?

Loading comments...