Back to blog
dns Published: AEU DNS Newsroom

India routing security deal signed by APNIC and NIXI

India routing security deal signed by APNIC and NIXI

APNIC and NIXI have signed an agreement to expand RPKI and IPv6 deployment in India, adding Route Origin Validation and training to fight route hijacks.

In a move that could make internet traffic in India harder to hijack, APNIC and the National Internet Exchange of India (NIXI) have signed a Memorandum of Understanding (MoU) to expand two key security technologies: IPv6 and the Resource Public Key Infrastructure (RPKI) (defined in RFC 6480). The agreement was signed on Tuesday, 8 September 2026, during APNIC 62 in Mumbai by APNIC Director General Jia Rong Low and NIXI Chief Executive Officer Dr Devesh Tyagi. Representatives from India's Ministry of Electronics and Information Technology, Department of Telecommunications, Internet Service Providers Association of India and APNIC Executive Council members witnessed the signing.

The MoU reflects a shared commitment to strengthening the security, resilience and long-term development of India's internet infrastructure. APNIC and NIXI will collaborate to increase deployment of IPv6 and RPKI by network operators and enterprises across India. IPv6 is the current generation of internet addressing, with a vastly larger pool of unique addresses than the older IPv4 system. RPKI is a cryptographic system that lets network operators prove they are authorized to announce specific blocks of internet addresses, making it much harder for an attacker to pretend to own a network they do not control. Planned initiatives include technical capacity building, development of local training infrastructure and knowledge sharing, all intended to support sustainable, locally led growth in internet expertise.

A central part of the collaboration is wider adoption of RPKI. India already has growing coverage of Route Origin Authorizations (ROAs), which are digitally signed records stating which network is allowed to announce a particular block of internet addresses. Building on that momentum, APNIC and NIXI will help network operators and enterprises deploy Route Origin Validation (ROV) (specified in RFC 6811), the second half of RPKI. ROV lets routers check every incoming route announcement against the ROA database and reject any announcement that is invalid. This directly strengthens protection against routing incidents and potential route hijacks, where traffic is sent to a network that has no legitimate claim to the destination. Under the agreement, NIXI will also work with APNIC to deploy an RPKI repository mirror inside India. This pilot project will assess whether a local mirror can improve access to RPKI data for Indian network operators and strengthen the resilience of the global RPKI repository system. The two organizations will also promote routing security best practices among network operators.

The MoU also establishes a framework for expanded technical training focused on IPv6 and RPKI. APNIC and NIXI plan to develop local training and laboratory infrastructure, and to set up a Train-the-trainer program that builds sustainable local expertise. Online and face-to-face training is anticipated for NIXI peering participants, affiliates of the Indian Registry for Internet Names and Numbers (IRINN), and other stakeholders across India.

APNIC Director General Jia Rong Low said India leads the world in IPv6 adoption and has the largest number of IPv6-enabled users. He attributed that achievement to the commitment of India's internet community, industry and government to building future-ready digital infrastructure. Through this partnership with NIXI, Low said APNIC looks forward to supporting the next stage of India's internet journey, working toward further IPv6 adoption and stronger routing security to support the long-term development of India's internet infrastructure. NIXI CEO Dr Devesh Tyagi framed the agreement as a significant step in NIXI's mission to build a secure, self-reliant and future-ready internet infrastructure for India. He said India's internet ecosystem is entering a new phase of scale and responsibility, and that infrastructure must lead from a position of strength, secure, resilient and built for what comes next. Tyagi noted that India is doing very well on RPKI ROAs, and that this partnership allows NIXI to build directly on that momentum by extending the focus to ROV. He added that India is committed to routing security and is a frontrunner in Autonomous System Provider Authorization (ASPA) adoption. ASPA adds another layer of routing security by verifying that a route announcement follows the legitimate chain of network providers.

Tyagi also made a practical point: because a small number of large network operators carry the majority of India's internet traffic, ROV adoption by those key networks alone can meaningfully secure the routing landscape for the economy as a whole. The partnership will help work closely with those networks, and with the wider operator and enterprise community, to build the technical expertise and infrastructure needed to safeguard the integrity of internet routing across the region.

For everyday internet users, the work described here is largely invisible, but it protects the path your data takes before it ever reaches a website, email server or DNS resolver. A route hijack can redirect traffic to a malicious server, intercept communications or cause outages. While encrypted DNS services such as AEU DNS protect the confidentiality and integrity of your DNS queries, they cannot prevent a route hijack by themselves, because the hijack happens at the network routing layer below the DNS. Businesses and website owners who want to reduce their exposure can start by asking their hosting provider or internet service provider whether they have deployed Route Origin Validation. For deeper, hands-on review of internet-facing infrastructure, AEU-I, a security-first IT and infrastructure consultancy, helps organizations assess and harden their internet-facing systems.

Terms explained

IPv6
The newer, much larger numbering system for internet-connected devices, created because the older IPv4 system ran out of unique addresses.
RPKI
Resource Public Key Infrastructure, a security system that uses digital certificates to show which network is allowed to advertise a particular block of internet addresses.
ROA
Route Origin Authorization, a digitally signed record that says a specific network may announce a specific block of internet addresses.
ROV
Route Origin Validation, a check performed by internet routers that rejects route announcements not covered by a valid ROA, blocking some route hijacks.
ASPA
Autonomous System Provider Authorization, a security mechanism that verifies the legitimate chain of providers for a route, preventing fake paths through unauthorized networks.

How to protect yourself

  1. Bookmark your bank, email and other important websites and type the address yourself instead of clicking links in messages, so a hijacked route or fake link cannot send you to a lookalike page.
  2. Before entering a password or payment details, check that the address bar shows a padlock and the correct website name, and never click through a browser warning about a bad certificate.
  3. Use a trusted encrypted DNS service such as AEU DNS on your devices, because it prevents someone from tampering with the internet address lookups that happen before a page loads.
  4. If you run a website, ask your hosting provider or internet service provider whether they have turned on Route Origin Validation, the check that rejects fake internet routing announcements.
  5. Keep your operating system and browser updated so that built-in security features can warn you about suspicious redirects or fake sites.
Get private, encrypted DNS