FINDING · DEFENSE
A linear-programming Matching Selection algorithm pairing ROA-covered clients with ROV-enforcing guard ASes (and vice versa) achieves 48.47% of all client-relay pairs with full ROA+ROV protection using parameters l=0.8, d1=0.9, d2=0.7, B=1.5—a multifold increase over vanilla Tor's base rate. The algorithm is constrained so no relay exceeds θ=5× its vanilla selection probability, bounding guard placement attack risk.
From 2025-lu-rpki-based-location-unaware-tor — RPKI-Based Location-Unaware Tor Guard Relay Selection Algorithms · §5.3 · 2025 · PoPETs 2025
Implications
- Full BGP-hijack resistance requires both ROA (prefix authorization) and ROV (route filtering at the AS); designing relay selection to co-locate client and guard in mutually ROV-enforcing ASes provides deterministic rather than merely probabilistic hijack protection.
- Implementing the matching optimization at directory authorities and distributing per-subcategory weight tables to clients (keyed only on client ROA/ROV status, not location) preserves anonymity while enabling stronger routing security.
Tags
Extracted by claude-sonnet-4-6 — review before relying.