Back to Blog

China Rolls out the ROAs

feature-rpki-rov-china

Summary

Long a laggard in RPKI adoption, China has dramatically increased its ROA coverage from 4% to 81% since April, signaling a major commitment to securing the internet’s routing system. This post explores the dramatic shift marking a significant milestone in global routing security, helping to protect networks from BGP routing mishaps that cause internet disruptions.


In the long-running effort to secure the internet’s routing system, RPKI Route Origin Validation (ROV) has played a central role. The success of its global adoption has been a contributing factor in reducing major disruptions caused by BGP routing mishaps.

Up until recently, the largest segment of the global internet that hadn’t yet embraced the technology was China. In this post, we’ll take a look at China’s sudden embrace of RPKI ROV by deploying Route Origin Authorizations (ROAs) for the vast majority of its BGP routes in a matter of weeks.

Background

As we’ve covered in previous posts, the deployment of RPKI ROV involves two steps: resource owners creating ROAs that define the proper origin AS of IP address space, and then networks (ASes) rejecting routes that don’t conform to those definitions. In recent years, we’ve documented the measurable progress made on both fronts.

Beginning several years ago, the majority of internet traffic is destined for RPKI-valid routes. Our analysis showed that RPKI-invalid routes rarely achieve propagation beyond a third of the internet due to the number of major ASes currently rejecting those routes. RPKI ROV works silently in the background, actively suppressing errant BGP announcements before they can cause further disruption, as evidenced by the recent leak of a BGP hijack of Telegram in India.

Here comes China

RPKI ROV deployment has been uneven at times, varying greatly from network to network and country to country. In terms of ROA coverage of routes, the Korean peninsula is divided in two halves with a counterintuitive 100% coverage in the reclusive North and nearly 0% in the hyper-advanced South. In fact, last March, a misconfiguration during North Korea’s rollout of a ROA to cover the country’s four /24 IPv4 routes led to a national outage of the country’s tiny internet.

But the big laggard in terms of national ROA creation has been China. That is, until a few weeks ago. Since April, China’s national internet registry CNNIC has been furiously publishing ROAs for the country’s major internet service providers. The result has led to a dramatic jump in ROA coverage, going from 4% to 81% according to statistics from APNIC Labs, pictured below. RIPEstat and Cloudflare Radar each provide their own views into this year’s spike in Chinese ROAs.

So dramatic was the change that the effort increased ROA coverage in the entire APNIC region (which includes most of Asia as well as Oceania) from 55% to 77% as is depicted below by the NIST RPKI Monitor site.

From a traffic standpoint, the impacts are just as profound. Kentik tags RPKI evaluation of each NetFlow upon ingestion, and when we aggregate across our dataset for traffic destined to China by RPKI evaluation, we arrive at the graphic below, which suggests a crossover point sometime last May.

Using data from the eminently helpful RPKIviews.org site, we can take a deeper look into the growth of ROAs published by CNNIC by origin between April 1 and July 20 of this year.

Under RPKI, a resource holder authorizes an ASN to originate a prefix by publishing a signed Route Origin Authorization (ROA). Relying parties — routers and validators — don't consume ROAs directly; they flatten each one into a set of Validated ROA Payloads (VRPs), simple (prefix, ASN, maxlen) triples that get checked against BGP announcements. A single ROA object can bundle many prefixes, so it can expand into many VRPs — one ROA, thousands of VRPs.

CNNIC’s total published VRPs jumped from 2,336 to 95,535 (41x growth) over the ~3.5 months between the two snapshots — 93,685 added, 486 removed, 798 re-issued (same prefix/ASN/maxlen, new ROA hash). The growth was concentrated in a handful of massive ROAs covering large numbers of Chinese-network ASNs. Per-ASN VRP counts (old → new), sorted by growth:

Name ASN April 1, 2026 July 20, 2026 delta
China Mobile (Backbone) AS9808 100 20,761 +20,661
China Mobile (Jiangsu Province) AS56046 11 5,312 +5,301
China Mobile (Zhejiang Province) AS56041 6 4,255 +4,249
China Telecom (Jiangsu Province Suzhou Network) AS140292 0 3,094 +3,094
Hebei Mobile (China Mobile in Hebei Province) AS24547 6 3,012 +3,006
China Telecom AS4134 4 2,768 +2,764
China Mobile Group Hunan Company AS56047 6 2,423 +2,417
China Unicom (Guangdong Province Network) AS17622 2 2,321 +2,319
Tencent Cloud AS45090 2 2,316 +2,314
China Unicom AS4808 36 2,277 +2,241

The single biggest driver is one ROA object, which alone went from 69 VRPs (April) to 19,975 VRPs (July), apparently a mega-ROA bundling a huge number of prefix authorizations for AS9808.

Several other China Mobile/Telecom/Unicom-adjacent ASNs (56044, 4837, 4811, 24444/24445, 24400, 17623, …) show similar 100-2000x growth in the same window. The number of distinct ASNs with any CNNIC-issued VRP also grew from 290 to 806. Alongside the routable-VRP growth, CNNIC’s AS0 VRPs (which signal that a prefix is not authorized to be originated by any ASN) grew from a single entry in April to 439 by July.

Conclusion

In the years between the major routing leak of April 2010 and the Safe Host leak in 2019, China Telecom was involved in several major routing leaks contributing to the country’s reputation as the bogeyman for BGP malfeasance. However, in late 2020, China Telecom joined the MANRS effort, committing to improving its routing security practices. And since then, no major leaks involving a Chinese telecom have occurred, suggesting that many of those incidents were likely nothing more than the result of insufficient routing safeguards.

RPKI ROV seemed to be something where China was lagging. Despite the growth in adoption around the world, and especially in the APNIC region, ROA coverage for China was almost zero. But by creating ROAs covering nearly its entire internet, China moves to join much of the rest of the world in leveraging RPKI to help protect its networks from routing mishaps that can cause disruptions.

Deploying ROAs at this scale is unprecedented. It is a milestone not just for China, but for the global internet.

Explore more from Kentik

We use cookies to deliver our services.
By using our website, you agree to the use of cookies as described in our Privacy Policy.