Summary
- RFC 827 made an unusually productive promise: gateways inside an autonomous system could use a private routing method that outsiders did not need to implement. Agreement was required at the boundary, not throughout the network.
- EGP exchanged neighbour status and reachability, not a complete routing algorithm, trusted common metric, path proof or policy language. Its first core-and-stub arrangement therefore depended on a privileged centre and, later, substantial operational controls outside the protocol.
- NSFNET’s meshed growth made those limits concrete. Bilateral representation agreements, policy databases, filters and alarms compensated for missing evidence until BGP carried sequences of autonomous systems with route claims.
- An autonomous system was a routing-responsibility boundary, not a title deed, sovereign territory or corporate identity. Its lesson is that decentralization needs both local freedom and enough shared evidence to make local rejection possible.
A number in a gateway header
In 1982, autonomy appeared in a prosaic place: a field in messages exchanged by gateways. RFC 827 described an “autonomous system” as a set of gateways administered by one authority and using whatever internal routing method that authority chose. The interior method was private. It did not have to be implemented elsewhere, explained to every neighbour or standardized for the whole Internet.
BBN’s place in this account is specific rather than proprietary. Eric Rosen authored RFC 827 from BBN, locating the first formal boundary inside the contractor and research environment that built major parts of the DARPA gateway system. That provenance does not make BBN the owner of autonomous systems or of the Internet; later NSFNET operations and BGP work involved different institutions and implementations.
That is a more exact origin than the later romance of thousands of equal networks. The immediate architecture was asymmetric. Gateways associated with ARPANET and SATNET formed a core. Other systems attached as stubs, asking that core to carry traffic among them. A stub should not become a transit route between other systems. The centre still had a special role.
Yet the same RFC contained the seed of its own obsolescence. It anticipated a future in which autonomous systems might be co-equal, with no system suitable as a universal core. The boundary was designed before the topology had caught up.
The important invention was not administrative isolation. A system remained useful only because it exposed a narrow interface. Its gateways identified neighbours, established an exchange, reported which networks were reachable through which gateway and monitored whether the neighbour was still alive. Local freedom existed beside an exterior obligation.
What EGP refused to decide
The name can mislead. EGP was not the algorithm that calculated the Internet’s best routes. RFC 827 said it exchanged information that routing algorithms would probably need. RFC 904 then specified neighbour acquisition, reachability monitoring, polling and updates in more detail.
The distinction protected heterogeneity. One system could change its internal algorithm without requiring a synchronized upgrade everywhere else. A campus, contractor network or backbone did not have to disclose its entire internal topology. Only the boundary behaviour had to remain intelligible.
But the narrowness created a hard limit. EGP distance values were comparable only when they came from the same autonomous system. There was no trusted common metric by which a receiver could rank claims from independent administrations. The protocol did not carry the complete sequence of autonomous systems a claim had crossed. Nor did it express the commercial or institutional reason one route should be accepted and another refused.
RFC 975 called EGP an interim mechanism. Its comfortable world resembled a tree: one route between systems, no arbitrary loops, no need to reconcile competing paths using a universal measure that nobody had agreed to trust. Autonomy had been recognized, but the evidence exchanged between autonomous actors was still too weak for a richly connected federation.
The core was a topology and a trust model
The early core did more than forward packets. It reduced ambiguity. Stub systems could treat the core’s representation of other stubs as the shared map. That arrangement avoided some loops precisely because alternative inter-system paths were constrained.
The cost was institutional. A route announced into the core could affect everyone depending on the core’s view. A system that had not agreed to carry traffic could be falsely represented as a route to somewhere else. A new bilateral connection could create information that the old spanning-tree assumption could not safely describe.
By 1989, the new NSFNET backbone made the mismatch visible. RFC 1092 said directly that the old core concept was deficient in a meshed environment. Its authors were not writing a philosophical critique. They were describing operational exposure: EGP permitted a gateway to represent networks without supplying enough proof that it was entitled to do so, and it could not represent policy with the precision the backbone required.
The remedy was not one magic protocol switch. NSFNET operators surrounded EGP with governance machinery. Regional networks entered bilateral agreements defining what they could represent. A policy database recorded the authorised relationships. Core routers used filters derived from that information. The network operations centre watched alarms and investigated inconsistent announcements. Unique AS numbers tied messages to routing administrations.
This was executable institutional design. Contracts defined responsibility; a database made the responsibility legible to operations; filters turned the record into local rejection; alarms exposed deviations. The common protocol remained thin, but its missing semantics did not disappear. People and systems carried them elsewhere.
A mesh punished invisible assumptions
In a tree, an incomplete description may appear adequate because there are few plausible alternatives. In a mesh, the same omission becomes a choice among rival claims.
Suppose a regional system hears that a destination is reachable through two peers. EGP can report reachability. Its numbers do not provide a universal comparison across the two administrations. If either peer repeats information learned through the other, the receiver lacks a complete AS path with which to identify the loop. The operator must know more than the packet says.
RFC 1093 documents different trust arrangements at NSFNET boundaries. Some neighbours could announce only networks recorded for them. Some relationships needed more permissive treatment. Routes could be suppressed, fixed metrics applied and database entries reviewed. The protocol interface was common; trust remained local and conditional.
That distinction is easily lost in present-day language. “Autonomous” never meant that a network could announce anything and demand acceptance. It meant the network controlled its own routing decisions while other networks retained the corresponding freedom to reject its claims. Autonomy existed on both sides of the session.
The AS path changed the evidence surface
The first BGP specification, RFC 1105, made a decisive piece of evidence travel with reachability: a sequence of autonomous systems. From the collected sequences, a receiver could construct an AS graph, discard a route containing its own AS and apply policy to the systems named in the path.
This did not make routing objective. It made a class of local decisions possible without a permanent oracle. Networks could still prefer customers over peers, avoid a particular transit provider, or decline to carry traffic. BGP did not remove policy; it gave policy a path-shaped object on which to operate.
Nor did the AS path prove every statement about origin, ownership or authorization. It showed the advertised traversal of routing boundaries. False information, configuration mistakes and strategic behaviour remained possible. Filters, contracts, registries, monitoring and judgement did not vanish when BGP arrived.
What changed was the location of crucial knowledge. Under the old model, the privileged core and its surrounding operational database supplied much of the context. With path-vector exchange, each participating system received more of the evidence needed to detect a loop and make its own policy choice. The centre could stop being the centre because part of the centre’s knowledge had become portable.
Do not mistake the boundary for the owner
Later guidance, including RFC 1930, defined an AS through a clearly expressed external routing policy and advised against assigning a separate number when no distinct policy was needed. That operational test matters.
An AS number does not prove that one company owns every router behind it. A multinational firm may operate several ASes; several organizations may share operational arrangements; a network may depend heavily on an upstream while retaining its own routing policy. The identifier is not sovereignty, incorporation, asset title or physical geography.
It is a compact answer to a narrower question: which routing administration is responsible for the policy presented at this boundary? Treating the number as more than that invites institutional overreach. Treating it as less erases the accountability that makes distributed routing possible.
Sources and evidence limits
- https://www.rfc-editor.org/rfc/rfc827.html
- https://www.rfc-editor.org/rfc/rfc904.html
- https://www.rfc-editor.org/rfc/rfc975.html
- https://www.rfc-editor.org/rfc/rfc1092.html
- https://www.rfc-editor.org/rfc/rfc1093.html
- https://www.rfc-editor.org/rfc/rfc1105.html
- https://www.rfc-editor.org/rfc/rfc1126.html
- https://www.rfc-editor.org/rfc/rfc1771.html
- https://www.rfc-editor.org/rfc/rfc1930.html
- https://www.rfc-editor.org/rfc/rfc5773.html
These RFCs document designs, requirements and named operational practices; they are not a complete deployment census. RFC 827’s co-equal future was an expectation, not a timestamp for the disappearance of every core function. RFC 1105 explains the first BGP design; later BGP-4 behaviour must not be projected backward into 1982.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
