Summary

  • A new numbering service should not become interoperable merely because an incumbent likes it, dislikes it less than a rival, or has political reasons to tolerate it. It should become interoperable only after it passes public, repeatable tests for uniqueness, security, migration safety, auditability, continuity and dispute notation.
  • Existing recognition history contains useful principles: a registry must have technical capacity, impartial treatment, documented policy, operational infrastructure and reliable coordination. The weakness is that the older regional model tied recognition to a single large territory and to incumbent migration, leaving little room for portable service competition after IPv4 scarcity and modern RPKI, RDAP and reverse-DNS dependence changed the risk.
  • Number Resource Society can turn its positive thesis into a public assurance agenda: campaign for every RIR or qualified provider to trace entries to recognised IANA and RIR history, quarantine conflicts, rehearse holder moves, document key and endpoint recovery, and let independent auditors rebuild consequential state from public commitments plus protected evidence.
  • The prize is not permission for NRS to govern networks or operate a registry. The prize is narrower and more valuable: NRS research can give operators a source-of-truth comparison, while ICANN, IANA, the NRO, RIRs and competent legal authorities keep responsibility for recognition and operational decisions.

Recognition should start at the test bench

The first room in which a future numbering service should seek recognition is not a boardroom. It is a test bench. An operator should be able to take a sample prefix, a sample autonomous system number, a sample holder change and a sample dispute, run them through the service, and see whether the result preserves uniqueness, explains authority, protects keys, keeps public discovery coherent and leaves an audit trail that another competent party can verify.

That test-bench principle matters because Internet number recognition is easy to romanticize. The public language around Regional Internet Registries often mixes history, community, territory, corporate form, policy tradition and technical service into one idea. A new service can be rejected as illegitimate because it did not descend from that lineage. It can also be accepted too quickly because it promises liberation from the failures of that lineage. Neither reaction answers the operational question: does the record remain safe, unique, portable and reviewable when people rely on it?

Number Resource Society is useful precisely because it sharpens that question. Its public charter presents number-resource institutions as bookkeepers whose legitimacy depends on accurate registration, voluntary reliance and limited authority rather than on claims to rule networks. That is an attractive advocacy position, but a charter is not operational assurance. The RIRs, IANA-facing services and any future qualified providers still have to prove that admission, key custody, correction and dispute rules are transparent and that portability proposals reconcile with the existing global history.

Recognition by proof sets a higher standard than recognition by friendship. NRS can ask IANA, ICANN, the NRO, RIRs and the operating community to define measurable conditions under which an authorised non-incumbent provider distinguishes a holder-controlled credential from an authoritative allocation, a transfer receipt from routing permission, a dispute note from a sanction and a service move from duplicate assignment. NRS supplies advocacy, member evidence and public scrutiny; it does not award recognition or discipline the institutions it studies.

The model is not anti-registry. It is anti-mystique. The current Internet Numbers Registry System is documented in RFC 7020, which describes distribution of globally unique IP address space and AS numbers and emphasizes registration accuracy. IANA's current number-resource page states that it coordinates global IP addressing systems and AS numbers, allocates pools to RIRs according to global policy, and does not ordinarily allocate directly to ISPs or end users. Those are facts to preserve, not myths to worship. Proof-based NRS advocacy would preserve those institutional facts while making service performance contestable.

What the old recognition model got right

The old recognition model should not be dismissed. ICP-2, the criteria for establishing a new Regional Internet Registry, required technical capacity, documented policy procedures, broad support in the proposed region, neutrality and impartial treatment. It required production-grade Internet connectivity, reverse-DNS support, suitable infrastructure and capable staff. It also required policies consistent with global goals of conservation, aggregation and registration.

Those requirements encode several durable truths. A numbering service must not be a private notebook. It must keep stable services online. It must be reachable by people who need the data. It must not treat equal requesters unequally. It must document the rules under which number-resource state changes. It must coordinate with other registries so that one resource has one current authoritative status. It must support reverse-DNS delegation and public registration services because downstream systems use them.

The weakness is not that ICP-2 cared about support and region. In the early regional expansion period, broad support from LIRs and migration of service agreements were practical ways to avoid split service inside a geographic area. The weakness is that the model was built around one registry per large region. It assumes that fragmentation is prevented by territorial monopoly rather than by a global root of uniqueness and strict interoperability tests. That assumption is now the very question under review.

IPv4 scarcity changed the economic stakes. Resource records are no longer merely administrative paths to future allocations. They are evidence used by buyers, lenders, cloud platforms, anti-abuse desks, upstream networks, courts, auditors, insurers and customers. RPKI changed the security stakes by connecting allocation authority and routing authorization. RDAP changed the discovery stakes by making structured registration data machine-readable and locatable through bootstrap registries. Reverse DNS remains a quiet dependency for mail, abuse handling and service onboarding. A new service must be judged against that full dependency stack.

The future recognition test should therefore keep the operational obligations of ICP-2 while separating them from territorial privilege. A service can prove neutrality without controlling a continent. It can prove technical capacity without becoming the only office in a region. It can prove community reliance through adoption, audit results, complaint outcomes and migration success rather than through incumbent consent. It can preserve global policy invariants without inheriting every discretionary habit of the old model.

The first proof is uniqueness

The numbering system's first invariant is uniqueness. There may be many opinions about who deserves a block, what a contract means, whether a sale should close, how much detail should be public, or which service provider is more efficient. There cannot be two valid current assignments of the same address range or the same AS number to incompatible holders. Once duplicate current state is normalized, the rest of the Internet pays the price in routing confusion, abuse handling, procurement failure and litigation.

The recognition standard NRS advocates must begin by proving that an authorised registry or provider cannot quietly accept duplicate current state. Every asserted resource must be checked against IANA registries, the relevant RIR or legacy history, public transfer logs where available, RDAP data, RPKI material and protected holder evidence. The responsible RIR or provider need not publish every document, but it must publish enough commitments, reasons and countersigned timestamps to show that a conflict was resolved, quarantined or marked as disputed.

Uniqueness proof also has to work at prefix boundaries. A /16 can contain transferred, leased, delegated, suballocated or disputed fragments. A status checker that treats a block as an indivisible label will miss overlap. A recognition test should include exact intervals, covered intervals, more-specific records, returned space, reserved ranges, legacy ranges, AS-number ranges and IPv6 aggregates.

It should simulate adversarial cases: two parties claim adjacent portions; one party claims a covering block after another has a more-specific operational record; a historic holder returns a block while stale RPKI material remains visible; a corporate successor claims capacity under a new legal name.

The proof should not become a secret trial. Some evidence will be private because it contains contracts, identity documents, security credentials or court material. But the public state can still identify the class of proof used, the date of review, the current status, the dispute flag if any, the hash commitment to protected evidence, the reviewing role and the appeal route. A cryptographic commitment does not prove truth, but it prevents a later record from being rewritten without leaving evidence of change.

Recognition by proof therefore flips the burden. NRS should not say, “accept us because we are the future.” It should tell every incumbent or proposed operator: let independent testers try to make your authorised service sign duplicate current status, miss a more-specific conflict, alter history without detection or hide a dispute as a clean allocation. When the responsible operator survives those tests, reliance begins to have a technical foundation.

Security proof must cover keys, people and recovery

Security cannot be reduced to a secure web site. A number-resource service touches multiple security layers: holder authentication, staff privileges, signing keys, RPKI objects, repository publication, RDAP service endpoints, reverse-DNS change requests, transfer approvals, dispute locks, backup integrity and emergency recovery. A service can have strong encryption and weak authority review. It can have hardware key storage and still allow a single insider to approve a dangerous state change.

NRS should publish and campaign for a security-proof standard covering both cryptographic and institutional controls. RIRs, RPKI certification authorities, repository operators and other authorised providers remain responsible for key ceremonies, separation of signing functions, rotation, revocation, recovery, tamper-evident logs, independent witness checkpoints, time-stamping, repository integrity and restoration. Their governance must also provide separation of duties, dual control, least privilege, conflict disclosure, protected audit records, incident categories and external testing.

The RPKI architecture in RFC 6480 is a useful discipline because it ties resource certificates to allocated IP addresses or AS numbers and allows route filters to be built from signed route-origin authorizations. It also exposes why recognition cannot be casual. A mistaken or captured resource certificate can affect the way networks evaluate route origin validity. NRS should explicitly disclaim RPKI authority and instead research how RIR and certification-authority practices affect hosted or delegated custody, transfer timing, revocation risk and holder-controlled keys.

Security proof must include failure exercises. What happens if a holder loses a signing key? What happens if two executives from the same company submit incompatible instructions? What happens if a court order freezes a claimed transfer? What happens if a registrar employee is compromised? What happens if a service endpoint is unavailable during a transfer window? What happens if a witness log is down but the registry is receiving urgent change requests? A service that has no published answer to these questions is asking for trust without a map.

The strongest NRS case is not that it can operate these systems. It is that its advocacy can force operational failures into view. An RIR, certification authority or qualified provider incident should identify the affected resources, time window, containment, customer notice, independent review and recovery record. NRS can compare those disclosures and represent affected members; containment and correction remain the duty of the operator and competent authorities.

Migration proof is where portability becomes real

Portability is easy to endorse in a speech and hard to perform at 02:00 when a holder's RDAP service, reverse DNS, RPKI certificates, abuse contact, lender file, customer allowlist and upstream filtering record all depend on coherent registry state. The value of NRS lies in campaigning for a tested exit right, documenting member experience and holding the responsible RIRs, IANA functions and authorised providers to a standard that avoids splitting the record or shocking relying services.

Migration proof should therefore be one of the central recognition tests advocated by NRS. The relevant RIRs, IANA-facing functions and authorised receiving provider should run a dry move between recognised service records, and reverse it where necessary, while preserving a single authoritative status. NRS can observe, publish the test method and collect member evidence, but it must not create an “NRS-served” authoritative record.

The test must distinguish three events that are often confused. A holder transfer changes the party with recognized rights or control. A service portability event changes the qualified service provider maintaining or publishing the record. A routing change alters how traffic is originated or accepted. A healthy system can change one without pretending to change all. A holder should be able to move registration service without automatically changing origin AS. A transfer should not become final simply because a route appears. A route should not become invalid merely because a service move is pending.

RDAP supplies a useful public lesson. RFC 9224 explains how clients find authoritative RDAP services through IANA bootstrap data and longest-match logic for IP address space. That does not create NRS authority. NRS can use it as evidence when urging IANA, RIRs and authorised RDAP operators to make every recognised discovery-pointer or service-status change independently verifiable.

Migration proof also needs customer continuity. A large network may have customers whose allowlists, procurement systems, mail reputation checks, DDoS scrubbing vendors and cloud bring-your-own-IP processes depend on stable registration data. NRS should document those member dependencies and advocate a migration package in which the responsible RIRs and providers identify changed and unchanged public fields, notices, stale services and the method for verifying final state.

The test should be repeated across hard cases: legacy IPv4, transferred IPv4, leased operating use, IPv6 assignments, AS numbers, corporate restructurings, insolvency instructions, RPKI delegated custody and reverse-DNS handover. A service that can only migrate a clean artificial example has not proved portability. A service that can migrate messy but lawful records with dispute controls and rollback has earned a more serious form of recognition.

Audit proof means strangers can rebuild the story

Auditability is not the same as transparency. Transparency says some records are public. Auditability says a competent stranger, with authorized access to protected evidence where appropriate, can rebuild the consequential story and detect unauthorized change. For numbering services, the story includes who asserted authority, what evidence was checked, what public status changed, what dependent services were affected, who approved the change, what objections were made, and how the final state was reconciled with the global record.

The audit proof proposed by NRS should start with a reconstruction exercise. Give an independent auditor a resource and a time period within an RIR or authorised provider. The auditor should reconstruct the old status, pending events, approved changes, rejected or quarantined claims, service endpoints, key transitions, dispute notes and public commitments without relying on oral assurances from the operator's management.

Append-only techniques help, but only if their limits are respected. RFC 9162, which defines a transparency-log model, describes signed tree heads, inclusion proofs and consistency proofs. Those tools can make equivocation detectable when monitors compare views. They do not prove that the underlying decision was correct. NRS should advocate their use as evidence controls by operators, not present them as a substitute for RIR policy, identity review, appeal or legal remedy.

Audit proof should have public and protected layers. The public layer can show current status, event class, time, reviewing role, non-sensitive reason category, dispute flag, service endpoint and cryptographic commitments. The protected layer can contain contracts, identity documents, invoices, board resolutions, court orders, security secrets or confidential transfer terms. The auditor can test the link between layers without publishing sensitive material.

External audit also needs independence. A service should not select only friendly reviewers, hide the scope, publish only compliments or bury adverse findings in vague language. The draft NRO RIR Governance Document Version 2 points toward periodic and ad hoc audits, summary reporting and emergency continuity. Whether that draft becomes final or changes, the direction is important: registry continuity should be testable by parties beyond management.

NRS can go further as an independent source of truth. It can publish proposed audit methods, compare public samples and redaction rules, track findings, deadlines and corrections, and campaign for RIRs and providers to give holders exportable event histories. The audited institutions, not NRS, must provide protected evidence and enable relying parties to verify public commitments.

Community support should mean adoption evidence

ICP-2 asks a candidate RIR to demonstrate broad support from LIRs in a proposed region. In a territorial model, that makes sense. A registry that is supposed to serve a continent cannot be imposed on a community that will not use it. In a portable-service model, however, community support should not mean permission from incumbents or an undefined consensus gathered by the same organizations whose monopoly is under examination.

For NRS advocacy, support should be measured through evidence of member mandate and institutional response. How many operators endorse the proposed tests? How many RIRs publish comparable data? How many auditors apply the method? How many providers support export and rehearsal? How many disputes are resolved without duplicate state? These measures concern whether its advocacy changes accountable practice; operational registry work remains with competent registries and providers.

Adoption evidence also prevents a familiar trap. Reformers often seek recognition from institutions that have incentives to deny or delay it. Incumbents can present their own non-cooperation as proof that a proposed safeguard lacks support. A proof-based model should not let the gatekeeper decide whether exit exists. If NRS substantiates its research, demonstrates member backing and persuades actual relying parties to use the resulting public comparisons, lack of incumbent enthusiasm should not be fatal to the reform case.

The reverse risk is capture by a narrow faction. A service can be popular among dissatisfied holders and still unsafe for the wider Internet. Adoption evidence must therefore be balanced with conflict tests, abuse handling, small-holder access, geographic spread, financial transparency, independent review, public security results and appeal outcomes. Recognition by proof is neither incumbent veto nor insurgent applause.

NRS's own first-party materials make this especially important. The NRS FAQ describes a global nonprofit membership organisation that campaigns, empowers and supports businesses around IP interests. The charter stresses bookkeeper limits, accurate registration and voluntary recognition. Those statements define an advocacy and member-representation role, not an RIR, NRO or registry-operator identity. NRS must keep its research source-backed and must not convert member loyalty into operational authority.

The right standard is therefore graduated influence. At the first level, NRS publishes source-backed research and member evidence. At the second, private parties may use those analyses in transfer, finance, insurance or procurement diligence. At the third, ICANN, IANA, the NRO or RIRs may adopt safeguards through their own authorised processes. At no level does an NRS publication become an authoritative allocation or registry record.

IANA can certify without becoming a political owner

IANA's current number-resource role is narrow and important. Its number-resource page identifies responsibility for global coordination of IP addressing systems and AS numbers, allocation of pools to RIRs under global policy, and documentation of IETF protocol assignments. It does not ordinarily allocate directly to ISPs or end users. That narrowness is a strength. The question is how a future recognition path can use IANA's uniqueness position without turning it into a political owner of every downstream dispute.

The answer is certification by invariant, not approval by favour. IANA-facing recognition should ask whether a service preserves global uniqueness, publishes coherent service endpoints, supports secure dependent services, provides evidence export, cooperates with emergency continuity, passes audit, exposes reasoned refusal categories and allows review. It should not ask whether the service shares the same politics as an incumbent or whether it promises to protect an existing regional monopoly from competition.

The 2016 SLA for IANA Numbering Services is an existing example of formal service accountability at a recognized boundary. It is between ICANN and the five RIRs, not between IANA and every holder. It does not create NRS rights. But it proves that number-resource service can be defined by agreements, service levels, review and escalation rather than by aura. Future recognition can extend that discipline: specify the service, measure the service, review the service, and define the consequence when the service fails.

IANA certification should also be modular. A service might first be certified for audit-log compatibility, then for supplemental holder receipts, then for migration rehearsals, then for live service-portability events under narrow conditions. A failed module should not destroy unrelated evidence. A successful module should not grant general authority. Modular recognition keeps the service honest because every claim has a defined scope.

That approach protects incumbents too. NRS cannot demand operational recognition by invoking reform language because it is not the operator. Its evidence and methodology must withstand scrutiny, while RIRs and qualified providers must pass the relevant uniqueness, security, migration and audit tests. Recognition remains a responsibility of authorised institutions rather than a political shield or advocacy award.

The operator's test is practical, not ideological

Network operators are not served by ideological purity. They need records that other networks, vendors, customers and authorities can trust. Before relying on an NRS report, an operator should ask a practical checklist about the underlying IANA, RIR and provider evidence. Can I prove that this resource is the same resource recognised in institutional history? Can I prove that no conflicting current claim is hidden? Can I export my evidence if I leave? Can the responsible provider recover after a key loss? Can route-origin authorisation survive a service change? Can customers verify public state without seeing confidential contracts?

The operator should also test latency. A record that is accurate but slow can fail a transaction. A court order, corporate closing, lender covenant, abuse emergency or customer migration may have a time window. NRS should campaign for RIRs and authorised providers to publish target and actual response times for high-risk changes, ordinary updates, dispute flags, emergency holds, audit responses and rollback.

Cost matters. A portable service that is technically elegant but priced only for large address holders would reproduce the same inequality it criticizes. Recognition proof should include access for smaller networks, clear fee classes, fee waivers or scaled assurance tiers, and public explanation of what each paid service covers. If audit, review and migration cost money, the cost should be visible rather than hidden inside discretionary friction.

Operators should test refusal. A fair registry service must sometimes say no: no to duplicate claims, forged authority, unverified corporate successors, unsafe key changes, abusive disclosure or emergency requests outside the defined standard. The quality of a service is shown not only by approvals but by reasoned refusals. NRS should track whether RIRs and authorised providers publish refusal categories, appeal routes, correction options and statistics, and represent members when those routes fail.

The final operator test is survivability. What happens if an RIR or authorised provider fails, loses funding, is sued, changes management, suffers a serious breach or becomes captured by a faction? NRS should press those operators to maintain escrow, successor rules, independent witness checkpoints, holder export and a sunset path. NRS itself should preserve its research archive and membership records, but it must not imply that those files are authoritative registry state.

Failure must be disqualifying when it threatens uniqueness

Proof-based recognition should be generous about experimentation and severe about core invariants. A new service can improve its user interface, reporting cadence, complaint categories or fee design without losing every form of reliance. It cannot be casual about duplicate current status, unauthorized key changes, hidden security incidents, public evidence falsification, refusal to cooperate with external audit or inability to export holder records.

The harsh line is necessary because number resources carry external effects. A bad state change does not harm only the service provider and its customer. It can affect route acceptance, mail delivery, abuse response, procurement checks, cloud onboarding, financing, customer continuity and cross-border litigation. The more the Internet relies on a record, the less tolerance there can be for invisible conflict.

Disqualification should also be bounded. If an RIR or certification provider fails an RPKI migration test, the relevant certificate function should face proportionate restrictions. If a registry operator fails an audit-log proof or accepts duplicate current status, authorised bodies should pause affected transitions, notify relying parties and trigger independent review. NRS can document the failure and campaign for proportionate consequences; it cannot freeze resources itself.

This is where patronage fails. A patronage system often tolerates an incumbent's failure because the incumbent is systemically important, while treating a new entrant's smaller failure as proof of unfitness. It also allows friendly exceptions. Proof-based recognition should publish the same classes for every qualified service: warning, cure, suspended module, emergency operator, handback, permanent loss of qualification and post-failure audit.

NRS should welcome this severity. A positive NRS thesis depends on applying hard standards even to reforms it supports. If it excuses weak evidence because a proposal is reformist, it weakens its own case. If its research survives adversarial review and the operational safeguards it advocates survive testing, operators gain reasons for confidence that do not depend on rhetoric.

Recognition by proof changes incentives

The largest benefit of proof-based recognition is not only that a new service can enter. It is that every existing service has to become more legible. Incumbents can no longer answer a portability proposal by saying that they are recognized and the challenger is not. They have to show their own security controls, auditability, migration safety, refusal reasons, service continuity and emergency readiness.

That discipline improves the current system without turning NRS into an operator. If NRS publishes a better proposed holder-export format, incumbents must explain weaker exports. If it documents stronger dispute-notation practices, incumbents must explain opaque freezes. If its research identifies faster secure correction elsewhere, an incumbent must justify delay. Competition in evidence quality is healthier than competition in political access.

It also changes IANA's role. Instead of deciding who belongs to a club, IANA-facing recognition can become an assurance ladder. Services that meet the ladder obtain narrowly defined interoperability. Services that fail lose that class of reliance. The ladder can be public, testable and reviewable. That is a more stable model than one in which recognition status is so hard to earn and so hard to lose that it becomes both a franchise and a shield.

The model does not solve every legal question. Property treatment, contract interpretation, secured lending, insolvency priority, sanctions and court authority remain jurisdictional and factual questions. A proof-based registry service can record a court order, a dispute status or a transfer evidence packet; it cannot make every court agree. That humility is part of the design. Recognition should preserve a clean record of commitments and evidence, not convert NRS into a world court, registry or NRO substitute.

The model also does not require the public to accept every NRS claim at once. Influence can be incremental: source-backed research, private diligence, software testing, auditor review, RIR-run service-portability pilots, public-discovery improvements and formally authorised recognition modules. A system that can only imagine total rejection or total authority has already conceded too much to patronage logic.

A qualification ladder can begin before formal authority

The practical path for NRS is an advocacy ladder, not a cliff. The first rung is voluntary member evidence: NRS can document how holders experience identity checks, transfers, corrections and service failures, cite recognised IANA and RIR records, and publish an explicitly non-authoritative research dossier. It should never issue a receipt that resembles an allocation or registry credential.

The second rung can be independent reconstruction. NRS can invite auditors and technical monitors to choose sample cases and test the chain from public records, consented member evidence and institutional commitments. The result is not a promise that every holder claim is correct. It is evidence that the research method preserves sources, discloses uncertainty and explains why a claim received its published assessment.

The third rung can be an observed dependency rehearsal run by the relevant RIRs and providers. For a resource whose recognised status remains unchanged, NRS can propose the test, recruit consenting member observers and publish results covering RDAP readiness, abuse-contact continuity, reverse-DNS coordination, RPKI key transition, notices, rollback and stale-data warnings. The authorised operators execute the rehearsal and retain control of every live system.

The fourth rung can be narrow use of NRS research by private parties. A broker or lender may consult an NRS case analysis alongside the authoritative RIR record. A cloud provider may use NRS reporting on dispute processes as a supplemental governance signal, while treating only recognised institutional records as authoritative. These uses do not bind IANA, an RIR, a court or any non-member.

The fifth rung can be formal pilot recognition for defined event classes. A pilot might allow a qualified registrar move for a limited set of low-conflict resources, with pre-filed rollback, independent monitoring and explicit statements that routing remains outside the ledger. Another pilot might allow emergency supplemental publication if an incumbent service is unavailable, without changing holder status. Each pilot should have entry criteria, publication rules, incident rules, termination rules and a public report.

This ladder is politically safer than a demand for instant equivalence. It gives the existing system a chance to match the improvements proposed by advocates. If an incumbent publishes better exports, faster corrections, clearer dispute states and stronger audits in response, NRS has already improved the market for evidence. If incumbents do not respond and NRS research keeps documenting the gap, the case for formally adopted safeguards becomes empirical.

The evidence standard must include adversarial cases

A soft demonstration is not enough. Any service can look safe when every applicant is cooperative, every resource is clean and every auditor is friendly. A recognition test should include adversarial cases designed to expose weak assumptions. The point is not to embarrass a candidate service. The point is to learn whether the service fails safely.

One adversarial case is stale authority. A person who once controlled a holder account presents old documents and demands a registrar move. A safe service checks corporate succession, current authority, revocation and competing instructions before issuing any public state change. If the evidence is incomplete, the service records a protected inquiry or a rejected request, not a clean event.

Another case is interval conflict. A covering block has a historic holder, a more-specific fragment has a current operating customer, and a third party claims to have purchased the whole covering block. A safe service does not flatten the conflict into one winner. It maps intervals, identifies which claims overlap, checks whether the more-specific use has separate authority, and quarantines disputed parts until the evidence class is resolved.

A third case is service blackmail. An outgoing registrar refuses to cooperate with a holder's move and warns relying parties that any new record is illegitimate. A safe portability design does not let the outgoing registrar veto exit by silence. It requires notice, gives the outgoing registrar a defined objection window, records any actual dispute, and allows the move if the holder's authority and dependency plan pass the objective tests.

A fourth case is reformer capture. A supporter submits a weak case and expects favourable NRS coverage because the organisation challenges incumbents. A credible advocacy body refuses to launder the claim and publishes its evidentiary reason. It proves independence by disappointing allies as well as opponents.

A fifth case is security compromise. An attacker obtains a holder credential and attempts to change service endpoints during a weekend. A safe service uses high-risk change controls, out-of-band confirmation, waiting periods or emergency review, and it leaves evidence of the attempt. The holder should be able to recover without the public record pretending the attack never happened.

These cases turn recognition into engineering discipline. NRS can publish independently sourced outcomes without exposing protected evidence, while clearly attributing each rejection, quarantine, provider objection and security containment to the RIR, operator, reviewer or legal authority that actually made the decision. Such disclosures would do more for trust than polished institutional language.

Patronage fails both sides of the dispute

Patronage is often defended as stability. The argument is that the existing institutions are known, that networks already depend on them, and that letting a challenger interoperate will create confusion. There is truth in the stability concern. Sudden unsupervised replacement would be reckless. But patronage is not the same as stability. Patronage protects the decision-maker's position. Stability protects the ledger's invariants.

The difference matters for incumbents. If an incumbent service is genuinely reliable, proof-based recognition will show it. Its public status will be coherent, its corrections timely, its security incidents handled, its audits clean, its migration rules fair and its emergency plans tested. Such an incumbent should not fear objective comparison. It should fear only a standard that gives equal credit to weaker evidence.

The difference matters for challengers. A challenger that faces patronage has an incentive to build politics around grievance. A challenger that faces proof has an incentive to build stronger records. NRS is more likely to mature as a trusted advocacy source if the path from claim to published evidence is visible and hard. If the only path is persuading incumbents to surrender privilege, every debate becomes existential. If the path is evidence and authorised institutional testing, reform can improve one safeguard at a time.

The difference also matters for users of the data. A cloud platform, abuse desk, broker, lender or public agency does not need to join a philosophical debate to evaluate a proof. It can ask whether the record has a conflict flag, whether a migration was rehearsed, whether the registrar is qualified, whether the event is current, whether the dependent services changed and whether an auditor can reconstruct the basis. These are practical questions with practical answers.

Patronage therefore weakens both accountability and confidence. It denies challengers a fair path while allowing incumbents to lean on inherited status. A proof regime is stricter but fairer. It tells NRS: your advocacy carries weight only to the extent that you can prove the claim. It tells incumbents and proposed providers: you remain trusted only to the extent that you can prove service. That is the bargain a numbering system under scarcity needs.

The positive NRS covenant

NRS can make a powerful offer to the Internet if it states the covenant plainly. We will not claim operational authority because we oppose incumbents, because our members are frustrated or because a political sponsor prefers us. We will research, campaign and represent members; authorised institutions must adopt and operate any resulting safeguards through their own accountable processes.

For uniqueness, NRS advocates single current state, overlap detection, conflict quarantine and public dispute notation by the responsible registries. For security, it advocates separated duties, protected keys, witnessed commitments, incident disclosure and tested recovery by certification and repository operators. For migration, it advocates RIR- and provider-run dry runs, customer continuity and rollback. For audit and governance, it advocates independent reconstruction, export rights, reasoned refusal, appeal and external review.

That covenant gives supporters a better argument. They no longer need to present NRS as a moral replacement for every RIR, or as a perfect answer to every historical grievance. They can present it as an advocacy organisation that earns defined trust through source-backed research, member representation and observed institutional outcomes. The more rigorous the proof, the stronger the positive thesis becomes.

It also gives skeptics a better objection. A skeptic should not need to say that no new numbering-service model can ever be considered because the existing system is the existing system. The skeptic can say: here is the uniqueness test the proposed operator failed; here is the migration case the responsible providers mishandled; here is the audit gap; here is the security recovery not demonstrated. Those objections are useful because NRS can correct its evidence or narrow the advocacy claim.

Recognition by proof is therefore more than an entry strategy. It is the constitutional principle for a portable numbering future. Incumbents should not be protected by patronage. Reformers should not be excused by idealism. The Internet should rely on a numbering service to the extent that the service proves the invariants on which everyone else depends.

Sources