The document discusses DNSSEC and RPKI. It provides an overview of DNSSEC, explaining how it uses public key cryptography and digital signatures to authenticate DNS data and verify the authenticity of DNS responses. It then discusses RPKI, explaining that it attaches ASNs and IP address blocks to X.509 certificates to validate the origination of IP routes announced in BGP. The certificates are issued based on resource allocations and signed based on the resource allocation hierarchy.