RPKI (Resource Public Key Infrastructure)

Resource Public Key Infrastructure (RFC 6480) is the cryptographic system that lets the holder of an IP prefix or AS number publish signed Route Origin Authorisations (ROAs). BGP routers can validate received announcements against ROAs and reject those that do not match, defeating accidental and malicious route hijacks. Operator adoption has grown sharply since 2020 and is now considered baseline routing hygiene.

Categories: Security ControlsThreats and AttacksProtocols and Standards

RPKI in context

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

To place RPKI in the wider telecom-security picture, review Cipher Downgrade Attack, HI2, Mediation Device (Lawful Interception), OAM, SCADA and UEA — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.