APNIC has integrated Autonomous System Provider Authorization (ASPA) into its Resource Public Key Infrastructure (RPKI) platform, giving network operators a new tool to verify BGP path integrity. ASPA objects allow an Autonomous System (AS) to publish a cryptographically signed list of its authorized upstream providers, which can then be used to detect route leaks and certain types of BGP hijacks that Route Origin Authorizations (ROAs) alone cannot prevent. Support is now live in MyAPNIC and the APNIC Registry API, making it available to all APNIC members immediately.
Background: The Border Gateway Protocol (BGP) is the routing protocol that directs traffic between autonomous systems on the public internet. RPKI, which includes ROAs, helps validate route origins but does not address path manipulation. ASPA extends RPKI by allowing networks to assert and verify provider-customer relationships along the AS path, adding a layer of path validation to the existing origin validation framework.
How ASPA works
ASPA objects are published in the RPKI alongside ROAs. When a network receives a BGP announcement, it can download ASPA records and check whether each AS in the path is authorized to propagate the route according to the published provider-customer relationships. If an AS path violates these relationships—for example, if a route moves from a provider to a customer and then back to a provider—the route is marked as ASPA-invalid and can be rejected or deprioritized.
The validation process does not require every AS along the path to perform ASPA checks. Even if upstream networks do not validate, downstream operators can still detect and reject invalid routes. This partial adoption model lowers the barrier to entry while still improving overall routing security.
Security benefits
ASPA addresses two key weaknesses in BGP security. First, it mitigates route leaks, where a network mistakenly propagates a route to an unintended peer. By validating the direction of route propagation against published provider lists, ASPA can detect and block these leaks before they propagate widely.
Second, ASPA makes certain BGP hijacks harder to execute. Attackers attempting to forge a route must either manipulate the AS path to appear consistent with ASPA records—which increases path length and reduces routing preference—or risk detection by networks performing ASPA validation. While not a complete defense against all hijacking techniques, ASPA raises the difficulty and reduces the attractiveness of such attacks.
Adoption and implementation
APNIC’s deployment is part of a broader effort across the Regional Internet Registries (RIRs). The RIPE NCC and ARIN have already added ASPA support, and all five RIRs are expected to offer it by the end of 2026. This alignment is critical for a technology whose effectiveness depends on global adoption.
Software support for ASPA is already available in open-source routing platforms like BIRD and OpenBGPD, and several commercial vendors are either shipping or developing implementations. However, public internet validation rates remain low, as most networks have not yet begun publishing ASPA objects or enabling validation in their routers. As more operators adopt the standard, validation coverage is expected to improve.
What to watch
Network operators should monitor ASPA adoption among their peers and transit providers. Early adopters can begin publishing ASPA objects through their RIR portals and configuring their routers to perform validation. While full protection requires widespread participation, even partial adoption can reduce exposure to route leaks and hijacks. Operators may also want to track software updates from their routing platform vendors to ensure ASPA support is available and enabled.
For professionals: ASPA validation can be implemented incrementally without disrupting existing routing. Operators should start by publishing their own ASPA objects and enabling validation in their edge routers. Over time, as more networks adopt the standard, the collective security benefits will grow. Monitoring tools that track ASPA-invalid routes can help identify misconfigurations or potential attacks early.
Automated pipeline · Cloud & Infrastructure
Synthesized from 1 industry feed on 9 Jul 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers ASPA deployment at APNIC.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers ASPA deployment at APNIC.
- Writing the article — Draft created article_id=304 slug=apnic-adds-aspa-support-to-rpki-for-bgp-path-validation
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states 'Support is now live in MyAPNIC and the APNIC Registry API, making it available to all APNIC members immediately.' The source confirms support is live but does not explicitly state 'immediately' or confirm universal availability to all members without qualification. The phrasing is defensible but slightly overstated.
- Style compliance: The 'Background' block is well-sourced but slightly exceeds the 2-4 sentence guideline (5 sentences). This is not material but should be tightened in future drafts.
- No copied phrasing: The draft avoids direct copying but echoes the source's list of routing platforms ('BIRD and OpenBGPD'). While the platforms are factual and the phrasing is generic, restructuring the sentence to avoid the list would better comply with the paraphrasing rule.
- Generating reader Q&A — Generated 5 items
- Assigning hero image — Reused library image reused image #13
- Linking related stories — Linked 3 relations from 250 candidates
- Publishing — Published apnic-adds-aspa-support-to-rpki-for-bgp-path-validation
- Mastodon — Posted https://mstdn.social/@hostingpaper/116889169529262395




Discussion · coming soon
Be the first to join the thread when community discussion launches.