PPASPA: Enhancing Internet Routing Security with Prefix Provider Authorizations
Abstract
ASPA (Autonomous System Provider Authorization), a recent mechanism for Internet route validation, allows an autonomous system (AS) to publish signed objects specifying which providers are authorized to announce its prefixes. However, because authorizations are defined only at the AS level, the mechanism becomes inflexible in scenarios involving multiple providers and distinct prefix policies. This work presents PPASPA, an extension to ASPA that enables prefix-specific authorizations, thereby covering practical situations not covered by the original model. We implement PPASPA in the BIRD routing software, preserving ASPA’s original AS-path validation logic while modifying only the mechanism used to identify authorized providers for prefix-specific policies. An evaluation using synthetic and trace-inspired scenarios shows that the computational overhead introduced by PPASPA is low, which may enable and facilitate its wide adoption on the Internet.References
Azimov, A., Bogomazov, E., Bush, R., Patel, K., Snijders, J., and Sriram, K. (2025). BGP AS PATH Verification Based on Autonomous System Provider Authorization (ASPA) Objects. Internet-Draft draft-ietf-sidrops-aspa-verification-22, IETF. Work in Progress.
Azimov, A., Uskov, E., Bush, R., Snijders, J., Housley, R., and Maddison, B. (2024). A Profile for Autonomous System Provider Authorization. Internet-Draft draft-ietf-sidrops-aspa-profile-18, IETF. Work in Progress.
Blunk, L., Damas, J., O’Donoghue, F., Gittings, B., Johns, M. S., and Sobrinho, J. L. (2005). Routing Policy Specification Language next generation (RPSLng). RFC 4012, IETF.
Borchert, O., Lee, K., Sriram, K., Montgomery, D., Gleichmann, P., and Adalier, M. (2021). Bgp secure routing extension (bgp-srx): Reference implementation and test tools for emerging bgp security standards. Technical Report NIST TN 2060, National Institute of Standards and Technology.
Bush, R. and Austein, R. (2017). The Resource Public Key Infrastructure (RPKI) to Router Protocol, Version 1. RFC 8210, IETF.
Butler, K., Farley, T., McDaniel, P., and Rexford, J. (2004). A survey of bgp security. ACM, draft version, 5:1–35.
Butler, K., Farley, T. R., McDaniel, P., and Rexford, J. (2010). A survey of BGP security issues and solutions. Proceedings of the IEEE, 98(1):100–122.
CZ.NIC (2026). Bird internet routing daemon. Acessado em: 26 de abr. de 2026.
Flechier, M., Heusse, M., and Duda, A. (2026). PAVA: BGP AS PATH Validation by Querying ASes about Their Relationships. Internet-Draft draft-flechier-sidrops-pava-01, IETF. Work in Progress.
Furuness, J., Morris, C., Morillo, R., Kasiliya, A., Wang, B., and Herzberg, A. (2025). Securing BGP ASAP: ASPA and other Post-ROV Defenses. In Network and Distributed System Security (NDSS) Symposium 2025. Internet Society.
Gao, L. and Rexford, J. (2001). Stable internet routing without global coordination. IEEE/ACM Transactions on Networking, 9(6):681–692.
Giotsas, V., Luckie, M., Huffaker, B., and Claffy, K. (2014). Inferring complex as relationships. In Proceedings of the 2014 Conference on Internet Measurement Conference, pages 23–29, New York, NY, USA. ACM.
Guo, Y., Wang, X., Xu, K., Liu, Z., and Li, Q. (2025). A Profile for Route Path Authorizations (RPAs). Internet-Draft draft-guo-sidrops-rpa-profile-00, IETF. Work in Progress.
Jin, Y., Scott, C., Dhamdhere, A., Giotsas, V., Krishnamurthy, A., and Shenker, S. (2019). Stable and practical as relationship inference with problink. In 16th USENIX Symposium on Networked Systems Design and Implementation (NSDI 19), pages 581–598. USENIX Association.
Kastanakis, S., Giotsas, V., Livadariu, I., and Suri, N. (2023). Replication: 20 years of inferring interdomain routing policies. In Proceedings of the 2023 ACM on Internet Measurement Conference, IMC ’23, pages 16–29, New York, NY, USA. Association for Computing Machinery.
Khadka, S. K. (2025). A first look at the adoption of bgp-based ddos scrubbing services. [link]. RIPE Labs, accessed from the article page.
Khadka, S. K., Bayhan, S., Holz, R., and Hesselman, C. (2026). Detecting and characterizing ddos scrubbing from global bgp routing: Insights from five leading scrubbers. In Passive and Active Measurement, volume 16477 of Lecture Notes in Computer Science, pages 17–43. Springer, Cham.
Lepinski, M. and Sriram, K. (2017). BGPsec Protocol Specification. RFC 8205.
NIST (2026). Robust Inter-Domain Routing. Acessado em 10 maio 2026.
Rekhter, Y., Li, T., and Hares, S. (2006). A Border Gateway Protocol 4 (BGP-4). RFC 4271, IETF.
Rekhter, Y., Li, T., Karrenberg, D., Terpstra, J., and Yu, J. (1999). Routing Policy Specification Language (RPSL). RFC 2622, IETF.
Rodday, N., Cunha, I., Bush, R., Katz-Bassett, E., Rodosek, G. D., Schmidt, T. C., and Wählisch, M. (2024). The resource public key infrastructure (RPKI): A survey on measurements and future prospects. IEEE Transactions on Network and Service Management, 21(2):2353–2373.
Testart, C., Wolff, J., Gouda, D., and Fontugne, R. (2024). Identifying current barriers in RPKI adoption. Technical report, Georgia Institute of Technology and Tufts University and IIJ Research Laboratory. Pre-print manuscript.
University of Oregon (2026). University of Oregon Route Views Project. Acessado em: 27 de janeiro de 2026.
Xu, K., Jiang, S., Guo, Y., and Wang, X. (2025). BGP AS PATH Verification Based on Route Path Authorizations (RPA) Objects. Internet-Draft draft-xu-sidrops-rpa-verification-01, IETF. Work in Progress.
Azimov, A., Uskov, E., Bush, R., Snijders, J., Housley, R., and Maddison, B. (2024). A Profile for Autonomous System Provider Authorization. Internet-Draft draft-ietf-sidrops-aspa-profile-18, IETF. Work in Progress.
Blunk, L., Damas, J., O’Donoghue, F., Gittings, B., Johns, M. S., and Sobrinho, J. L. (2005). Routing Policy Specification Language next generation (RPSLng). RFC 4012, IETF.
Borchert, O., Lee, K., Sriram, K., Montgomery, D., Gleichmann, P., and Adalier, M. (2021). Bgp secure routing extension (bgp-srx): Reference implementation and test tools for emerging bgp security standards. Technical Report NIST TN 2060, National Institute of Standards and Technology.
Bush, R. and Austein, R. (2017). The Resource Public Key Infrastructure (RPKI) to Router Protocol, Version 1. RFC 8210, IETF.
Butler, K., Farley, T., McDaniel, P., and Rexford, J. (2004). A survey of bgp security. ACM, draft version, 5:1–35.
Butler, K., Farley, T. R., McDaniel, P., and Rexford, J. (2010). A survey of BGP security issues and solutions. Proceedings of the IEEE, 98(1):100–122.
CZ.NIC (2026). Bird internet routing daemon. Acessado em: 26 de abr. de 2026.
Flechier, M., Heusse, M., and Duda, A. (2026). PAVA: BGP AS PATH Validation by Querying ASes about Their Relationships. Internet-Draft draft-flechier-sidrops-pava-01, IETF. Work in Progress.
Furuness, J., Morris, C., Morillo, R., Kasiliya, A., Wang, B., and Herzberg, A. (2025). Securing BGP ASAP: ASPA and other Post-ROV Defenses. In Network and Distributed System Security (NDSS) Symposium 2025. Internet Society.
Gao, L. and Rexford, J. (2001). Stable internet routing without global coordination. IEEE/ACM Transactions on Networking, 9(6):681–692.
Giotsas, V., Luckie, M., Huffaker, B., and Claffy, K. (2014). Inferring complex as relationships. In Proceedings of the 2014 Conference on Internet Measurement Conference, pages 23–29, New York, NY, USA. ACM.
Guo, Y., Wang, X., Xu, K., Liu, Z., and Li, Q. (2025). A Profile for Route Path Authorizations (RPAs). Internet-Draft draft-guo-sidrops-rpa-profile-00, IETF. Work in Progress.
Jin, Y., Scott, C., Dhamdhere, A., Giotsas, V., Krishnamurthy, A., and Shenker, S. (2019). Stable and practical as relationship inference with problink. In 16th USENIX Symposium on Networked Systems Design and Implementation (NSDI 19), pages 581–598. USENIX Association.
Kastanakis, S., Giotsas, V., Livadariu, I., and Suri, N. (2023). Replication: 20 years of inferring interdomain routing policies. In Proceedings of the 2023 ACM on Internet Measurement Conference, IMC ’23, pages 16–29, New York, NY, USA. Association for Computing Machinery.
Khadka, S. K. (2025). A first look at the adoption of bgp-based ddos scrubbing services. [link]. RIPE Labs, accessed from the article page.
Khadka, S. K., Bayhan, S., Holz, R., and Hesselman, C. (2026). Detecting and characterizing ddos scrubbing from global bgp routing: Insights from five leading scrubbers. In Passive and Active Measurement, volume 16477 of Lecture Notes in Computer Science, pages 17–43. Springer, Cham.
Lepinski, M. and Sriram, K. (2017). BGPsec Protocol Specification. RFC 8205.
NIST (2026). Robust Inter-Domain Routing. Acessado em 10 maio 2026.
Rekhter, Y., Li, T., and Hares, S. (2006). A Border Gateway Protocol 4 (BGP-4). RFC 4271, IETF.
Rekhter, Y., Li, T., Karrenberg, D., Terpstra, J., and Yu, J. (1999). Routing Policy Specification Language (RPSL). RFC 2622, IETF.
Rodday, N., Cunha, I., Bush, R., Katz-Bassett, E., Rodosek, G. D., Schmidt, T. C., and Wählisch, M. (2024). The resource public key infrastructure (RPKI): A survey on measurements and future prospects. IEEE Transactions on Network and Service Management, 21(2):2353–2373.
Testart, C., Wolff, J., Gouda, D., and Fontugne, R. (2024). Identifying current barriers in RPKI adoption. Technical report, Georgia Institute of Technology and Tufts University and IIJ Research Laboratory. Pre-print manuscript.
University of Oregon (2026). University of Oregon Route Views Project. Acessado em: 27 de janeiro de 2026.
Xu, K., Jiang, S., Guo, Y., and Wang, X. (2025). BGP AS PATH Verification Based on Route Path Authorizations (RPA) Objects. Internet-Draft draft-xu-sidrops-rpa-verification-01, IETF. Work in Progress.
Published
2026-09-01
How to Cite
DUQUINI, Sthefany C.; MARCOS, Pedro de B.; CUNHA, Ítalo; FERREIRA, Ronaldo A..
PPASPA: Enhancing Internet Routing Security with Prefix Provider Authorizations. In: BRAZILIAN SYMPOSIUM ON CYBERSECURITY (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 945-960.
DOI: https://doi.org/10.5753/sbseg.2026.28923.
