Skip to content

Archive

ASPA

1 articles
Cybersecurity 23 Sep 2026 5 min read

RPKI ASPA Authorizes Transit Relationships for AS_PATH Checks

A valid route origin says little about the relationships represented by the rest of an AS_PATH. A prefix can originate from an authorized AS and still travel through a sequence that conflicts with expected customer-to-provider structure. Autonomous System Provider Authorization, or ASPA, adds a signed RPKI object for that second problem. As of September 2026, ASPA is still specified in active IETF Internet-Drafts rather than a published RFC. The current ASPA profile draft defines the signed object, while the current verification draft defines procedures for applying validated ASPA data to BGP AS_PATHs. That status matters operationally: fields and procedures remain subject to change until the specifications complete the standards process.