团队文章权力与治理

Are your IP assets truly yours? Understanding control gaps in RIR allocations

See how address agreements, registry records and working routes differ, and why Lu Heng argues that keeping a record should not mean owning the network.

目录

A network operator and a record keeper examine matching blue markers beside separate network equipment and a records cabinet.
The operator runs the network; the registry maintains a record about it. The power to change that record can create dependence without becoming ownership of the network.

Imagine that your company has paid for an IPv4 block and built services around it. Customers connect to those addresses, engineers maintain the routes and partners have approved them in their security systems. Yet a different organisation maintains the registration record that other organisations consult. What, exactly, does your company control?

The question becomes easier when you separate three things: the commercial agreement for the addresses, the records describing their use and the network that carries the traffic. They interact, but none is a substitute for the other two.

Start with the service people depend on

An IPv4 address helps other systems find a service. An address block is a group of those addresses. Once customers put them into firewalls, monitoring tools or application settings, changing them can require work far beyond the company that operates the network.

Suppose a hosting company moves a customer's service to another provider. Copying the application may be straightforward. Preserving the address, updating routing arrangements and helping the customer's partners recognise the change are separate jobs. A completed purchase does not perform those jobs automatically.

This is why control should be tested through a real change: can the business keep serving people when a supplier changes, a record is disputed or the person managing the account leaves?

The recordkeeper and the operator do different work

A Regional Internet Registry, or RIR, maintains records for Internet number resources. A network operator builds and runs the systems that use them. A registry entry does not build a data centre, connect a customer or maintain an application.

Registration nevertheless matters because other organisations use records when checking an address block's history and the parties responsible for it. That reliance gives the recordkeeper practical influence. The question is how far that influence should extend.

In Note 72, Lu Heng argues that keeping a shared record does not give its administrator ownership of the underlying activity or a political mandate over its participants. A record should describe a relationship that can be verified. The institution maintaining it should not become the permanent source of permission for that relationship to exist.

This is the principle behind his criticism of registry power. Coordination is necessary; making every participant permanently dependent on one coordinator is a different choice.

A routing check answers a narrower question

Consider a route-origin authorisation, commonly called a ROA. It connects an address prefix with an autonomous system number, the identifier of the network authorised to originate that route. Other networks can use it when checking a route announcement.

The IETF's origin-validation specification defines Valid, Invalid and NotFound results and leaves routing policy to the receiving network. This check does not decide who owns a business, settle a commercial dispute or validate every part of a route's path.

A conflicting authorisation can affect how networks treat an announcement, depending on their policies. That makes authorisation records important to continuity. It does not turn them into an unlimited judgement about whether a company is entitled to exist.

Find the points at which someone else can interrupt continuity

Take one block your business uses and follow it through the operation. Who maintains its registration contacts? Who can change its routing authorisations? Which upstream networks carry it? Who has the evidence needed to resolve an inconsistency? Who will answer when a customer cannot connect?

The answers may involve several organisations. Put the responsibilities together rather than assuming that a purchase agreement covers them all. Keep the resource history, working contacts and change procedures usable by the people who actually maintain the service.

In Note 66, Lu Heng separates completing a transaction from keeping a resource usable afterwards. A transfer can close on a particular day; continuity remains a job the next morning and every day after it.

Make the administrator replaceable

Lu Heng's wider proposal is that coordination should preserve uniqueness and verifiable history while allowing its administrator to be replaced. If participants can check the relevant facts and continue using their resources through a change of coordinator, an administrative relationship becomes less capable of holding their operations hostage.

That is a proposed direction for Internet coordination, not a claim that exporting a registry file today makes every network accept it. The practical challenge is to preserve both evidence and interoperability through the change.

For a business, the immediate lesson is to examine where continuity depends on another party's continuing cooperation. For the Internet, the larger question is why those dependencies should become permanent authority. Continue with Lu Heng's proposed rights for uniqueness coordination.