9 June 2014

Video: CrypTech and RPKI (Randy Bush at RIPE 68)

Andrew Mcconachie
By Andrew McconachieFormer Intern

How do we build an open hardware security module that’s verifiably secure? Can we use Openflow and BGP RPKI to enforce route validation in the data plane? In this two part lightning talk Randy Bush introduces two projects he and others have started. The first project is cryptech.is, an open reference design for hardware security modules that aims to be secure from government and private party intrusion. Randy lays out the goals of the project and solicits help from the community. The second project is a BGPSEC experiment being carried out in a New Zealand IXP. In the experiment an Openflow switch placed between two BGP peers is programmed exclusively with routes validated from a route server using RPKI. Randy’s talk, entitled “CrypTech and RPKI/Flow IX” is available for viewing, and the slides are available for download.

RandyBush_HSM_RPKI

After watching, check out our page on BGPSEC to learn more about deploying BGPSEC and RPKI.

Disclaimer: Viewpoints expressed in this post are those of the author and may or may not reflect official Internet Society positions.

Related Posts

Encryption 14 October 2025

Our Voices Are Making a Difference in the Fight for Strong Encryption

In the global movement to protect encryption, our voices matter. When we raise our voices together, we inspire and...

Encryption 25 July 2025

A UK Government Order Threatens the Privacy and Security of All Internet Users  

The Internet Society jointly filed a request in a UK court on Wednesday to provide expert evidence on privacy...

Encryption 25 July 2025

Encryption Makes Us Powerful: Internet Society Hosts Encryption Advocacy Workshop for European Civil Society 

In early February of this year, the Internet Society hosted an Encryption Advocacy Workshop in Brussels for European civil society...