ASPA (Autonomous System Provider Authorization)

What is ASPA

ASPA (Autonomous System Provider Authorization) is an RPKI object created by the holder of an Autonomous System Number (ASN).

An ASPA contains a signed list of authorized upstream providers. RPKI validators can retrieve ASPA records and use them to verify whether BGP AS paths match authorized provider-customer relationships.

By publishing this information, operators can help detect route leaks and invalid routing paths.

ASPA at a glance

  • Created by an ASN holder
  • Contains a signed list of authorized upstream providers
  • Supports validation of BGP AS paths
  • Builds on Route Origin Authorizations (ROAs)
  • Helps strengthen routing security

Why use ASPAs?

Internet routing relies on trusted relationships between networks.

While ROAs help validate route origins, they do not validate the path a route takes through the Internet.

ASPA enables operators to verify whether BGP AS paths match authorized provider-customer relationships.

This helps:

Reduce the risk of route leaks

Route leaks occur when routes are re-advertised in ways that do not follow expected routing policies. ASPA helps operators identify paths that do not match authorized provider relationships.

Strengthen BGP path validation

ASPA extends routing validation beyond route origins by helping operators validate routing paths.

Make routing information harder to manipulate

ASPA helps identify invalid routing paths and can make forged-path attacks more difficult.

Contribute to a more secure Internet

The more networks that publish ASPAs, the greater the opportunity to improve routing validation across the Internet.

Build on your ROAs with ASPA

Many operators already use ROAs as part of their routing security practices.

ASPA builds on those protections by helping validate routing paths as well as route origins.

Together, ROAs and ASPAs provide stronger routing security.

Adoption is underway

Since ASPA support launched through MyAPNIC and the APNIC Registry API:

  • More than 100 ASPAs have been created
  • Adoption spans 21 economies
  • Uptake continues to grow through community engagement and awareness activities
  • As more networks publish ASPAs, routing path information becomes more widely available for validation.

Take the next step

Whether you’re ready to create an ASPA or want to learn more first, APNIC provides resources and support to help you get started.

Create your ASPA

Create and manage ASPAs through MyAPNIC.

Create your ASPA in MyAPNIC

Learn more about ASPA

Read detailed guidance on creating, updating and managing ASPA objects.

Read the ASPA Help Centre guide

Read the launch article

Learn more about ASPA support in MyAPNIC and the APNIC Registry API.

Read the ASPA launch article

Need assistance icon

Need assistance?

APNIC Member Services can provide guidance and support.