The Border Gateway Protocol (BGP) lacks native mechanisms to verify that routes adhere to authorized paths. This makes the global infrastructure vulnerable to route leaks, which have caused several major Internet disruptions. Autonomous System Provider Authorization (ASPA) is an emerging technology, currently at Internet-draft stage, that extends the Resource Public Key Infrastructure (RPKI) by allowing ASes to cryptographically declare their upstream providers; prior work has shown its effectiveness in detecting route leaks and certain forms of path manipulation. Yet, as ASPA moves toward standardization and Regional Internet Registries enable it in their RPKI dashboards, its actual deployment, operational dynamics, and alignment with independently inferred relationships remain unstudied. In this paper, we present the first measurement study of real-world ASPA deployment, tracing the evolution of 1646 adopting ASes from October 2023 to March 2026. We further introduce a methodology to apply ASPA AS Path verification—originally designed for live BGP routers—to passively collected BGP data, and use it to identify thousands of potential route leaks across nearly 57 million AS Paths. Finally, we compare ASPA-declared providers against two publicly available datasets of inferred providers, and find a recall up to 93 % when accounting for our limited visibility into the routing ecosystem.
A First Look at ASPA: Deployment, Route Leaks, and AS Relationships / Farina, M., Trevisan, M., Bartoli, A.. - (2026), pp. 903-919. (2026 ACM Internet Measurement Conference Karlsruhe, Germania 12-16 ottobre 2026) [10.1145/3777912.3839812].
A First Look at ASPA: Deployment, Route Leaks, and AS Relationships
Mauro FarinaPrimo
;Martino TrevisanSecondo
;Alberto BartoliUltimo
2026-01-01
Abstract
The Border Gateway Protocol (BGP) lacks native mechanisms to verify that routes adhere to authorized paths. This makes the global infrastructure vulnerable to route leaks, which have caused several major Internet disruptions. Autonomous System Provider Authorization (ASPA) is an emerging technology, currently at Internet-draft stage, that extends the Resource Public Key Infrastructure (RPKI) by allowing ASes to cryptographically declare their upstream providers; prior work has shown its effectiveness in detecting route leaks and certain forms of path manipulation. Yet, as ASPA moves toward standardization and Regional Internet Registries enable it in their RPKI dashboards, its actual deployment, operational dynamics, and alignment with independently inferred relationships remain unstudied. In this paper, we present the first measurement study of real-world ASPA deployment, tracing the evolution of 1646 adopting ASes from October 2023 to March 2026. We further introduce a methodology to apply ASPA AS Path verification—originally designed for live BGP routers—to passively collected BGP data, and use it to identify thousands of potential route leaks across nearly 57 million AS Paths. Finally, we compare ASPA-declared providers against two publicly available datasets of inferred providers, and find a recall up to 93 % when accounting for our limited visibility into the routing ecosystem.| File | Dimensione | Formato | |
|---|---|---|---|
|
farina2026first.pdf
accesso aperto
Licenza:
Creative commons
Dimensione
1 MB
Formato
Adobe PDF
|
1 MB | Adobe PDF | Visualizza/Apri |
Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


