团队文章互联网怎样运作

APNIC explained: what it does, what it controls, and why it matters

A beginner’s guide to APNIC’s number resources, registry services, institutional limits, and Lu Heng’s case for accountable, replaceable Internet coordination.

目录

An archivist checks a card beside a filing cabinet; nearby devices connect homes through blue cables.
APNIC's registry services help networks coordinate. The operators, rather than the register, carry traffic between connected systems.

APNIC stands for the Asia Pacific Network Information Centre. It is one of the five Regional Internet Registries, the organisations that distribute and register the numbers networks use to identify themselves and send data across the Internet.

Its work is easy to overlook when a connection is working. A network needs addresses other networks can recognise, records identifying who controls them, and ways to check whether a route announcement is authorised. APNIC provides important parts of that shared machinery in Asia and the Pacific.

That explains why APNIC matters. It also raises the question at the centre of Lu Heng’s writing: when everyone depends on a common record, how do we keep its administrator from acquiring power beyond the job of maintaining it?

Start with the numbers, not the acronyms

Imagine a new Internet provider preparing to connect its customers to other networks. It needs more than cables and servers. The wider Internet must be able to distinguish its destinations and recognise its network.

  • IPv4 addresses identify destinations using the older, 32-bit addressing system. Its limited address space has made allocation, transfers and efficient use important operational concerns.
  • IPv6 addresses perform the same basic addressing job in a much larger, 128-bit space. Deploying IPv6 requires working network support; the size of the address space alone does not connect two systems.
  • An Autonomous System Number, or ASN, identifies a network that exchanges routing information with other networks. An IP address identifies a destination; an ASN helps identify the network announcing how to reach it.

APNIC allocates or assigns these resources and maintains registration records under the applicable policies. The provider operates its connections and exchanges traffic with other networks. The registry does not carry every packet or centrally select every route.

Where APNIC fits in the wider Internet

APNIC describes itself as an independent, not-for-profit membership organisation serving 56 economies across Asia and Oceania. The other four Regional Internet Registries are AFRINIC, ARIN, LACNIC and the RIPE NCC. At the global level, the IANA functions maintain the top-level number registries and make allocations to the regional system.

Some operators work through a National Internet Registry, or NIR. APNIC lists seven: APJII in Indonesia, CNNIC in China, IRINN in India, JPNIC in Japan, KISA in South Korea, TWNIC in Taiwan and VNNIC in Vietnam. These are separate organisations within the existing regional arrangement, not APNIC branch offices. They can provide services in local languages and contexts while participating in APNIC’s policy framework.

The choice between APNIC and an NIR depends on the applicable arrangements. It should not be confused with a general right to leave the registry system while retaining every existing resource and service relationship. That wider freedom is one of the questions Lu Heng wants a future system to address.

What its services actually do

Registration becomes useful through services that operators can consult and other systems can check. Each has a distinct job:

  • WHOIS and RDAP: ways to look up registration information, such as an address range, its registered organisation and contact details. RDAP supplies structured responses that software can use. If you are investigating an address, start with APNIC’s RDAP lookup. A registry entry does not show the path a packet took or necessarily identify the person using an address.
  • RPKI and Route Origin Authorisations: cryptographically verifiable records linking address resources to authorised route origins. A Route Origin Authorisation, or ROA, says which ASN may originate an address prefix. Operators can use this information to check announcements. It does not authenticate every network along the route or guarantee that traffic will arrive.
  • The Internet Routing Registry: a database where operators publish routing information and policy. Other operators can use those records when building route filters. Its usefulness depends on records being accurate and maintained.
  • Reverse DNS: delegation that allows an IP address to be looked up as a name. This is different from registering a domain name for a website. APNIC’s number-resource role does not make it a general domain-name registrar.

APNIC’s description of its activities also covers transfers, training and technical support. These services help people run networks. Their value comes from solving coordination problems, not from giving one institution ownership of the Internet.

Who makes the decisions, and who is affected?

APNIC has members, an elected Executive Council and a Secretariat that carries out its work. Its community policy process provides a way to propose and discuss number-resource policies. Understanding these different roles matters: a staff decision, a policy proposal and a board election are not the same kind of action.

But participation in an organisation is different from political representation of everyone affected by its decisions. A business may rely on an address supplied by its provider. Its customers may depend on that business without knowing that APNIC exists. A decision about a registration or authorisation can therefore have consequences well beyond the direct membership.

This is the boundary Lu Heng challenges. Serving a region does not, in his argument, grant an administrator a political mandate over that region. Keeping a shared record does not make the administrator the owner of all the activity built around it.

In Note 9, on APNIC governance, he connects his criticism to accountability, institutional structure and the practical ability of members to participate. His later Notes ask a deeper question: even with better leadership, should networks remain permanently dependent on a particular institution?

Why this becomes a practical problem

Return to the provider preparing to connect its customers. Over time, other organisations may build security rules, monitoring, route filters and customer connections around its addresses. Those relationships do not automatically move when an administrator, provider or policy changes.

The cost is therefore larger than replacing a number in a database. A poorly managed change can require independent organisations to update their systems at the same time. Correct registration records, routing authorisations and contact information all matter to a workable transition.

IPv4 scarcity makes these dependencies more visible because replacing address capacity can be difficult. IPv6 offers a far larger address space, but it does not by itself decide who controls records, how that authority is limited, or whether an operator can replace an administrator. Address supply and institutional power are related questions with different answers.

The distinction is between an essential function and an irreplaceable organisation. Networks need reliable coordination. That need is precisely why dependence on a single administrator deserves scrutiny.

The alternative: rules networks can verify and choose

Lu Heng’s proposed direction goes beyond moving the same powers to a new office. In Note 65, on running-code primacy, he argues for a small initial technical specification, verification by participating networks and voluntary adoption. Working implementations and the networks choosing to interoperate would carry coordination forward, without a permanent institution deciding which future choices are legitimate.

For a newcomer, the practical idea is this: agree on what must be checked for networks to work together, make those checks independently verifiable, and allow people to adopt a better implementation without surrendering their network identity.

Note 72, the Bill of Rights of Uniqueness Coordination, develops the corresponding boundaries. The common layer should establish uniqueness, evidence of control, accurate records, security and traceable changes. It should not turn those duties into a standing veto over business models or a claim to political rule.

These Notes propose a future coordination model. Achieving it requires alternatives that preserve uniqueness, verifiable records and operational continuity in practice. Simply abandoning accurate records would not meet that test. Neither would replacing the administrator while leaving everyone subject to the same permanent central approval.

Why the work cannot wait for a crisis

Every new service built on an existing identity can increase the cost of changing it. If the only available response to a failing institution is to disrupt working networks, the practical freedom to leave becomes weaker as dependence grows.

Building an alternative takes time. Operators need to know which records and authorisations their services rely on, what others would need to verify, and how a transition could keep customers connected. These are questions to resolve while networks are working, not discoveries to make during an outage or institutional dispute.

That is the larger reason to understand APNIC. Its services show what Internet coordination must accomplish. Lu Heng’s challenge is to preserve those useful functions while making their administration limited, accountable and replaceable.

To follow that argument from the institutional question to the proposed technical direction, continue with Note 65: why working networks should remain the source of Internet coordination.