Digital Emblems-When markings are required, but you have no rattle-can
Bill Woodcock
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In his DEF CON 32 talk, "Digital Emblems: When markings are required, but you have no rattle-can," Bill Woodcock introduced a novel concept designed to modernize and secure the myriad physical markings mandated by international law. Addressing a fundamental challenge in an increasingly digital world, Woodcock detailed an ongoing Internet Engineering Task Force (IETF) initiative to create "digital emblems." These emblems are intended to supplement, and potentially replace, traditional physical markings that identify protected assets, regulated goods, or authorized entities under various international conventions. The core problem this work seeks to solve is the inherent limitations of physical markings in terms of verifiability, machine readability, and applicability to non-physical assets like digital data or online services.

Key moments
- 0:00 Introduction to digital emblems and physical marking examples
- 3:06 Inherent problems and limitations of physical markings
- 4:40 Addressing the problem of proprietary scanners at borders
- 6:04 Diagram of digital emblem components: issuer, asset, validator
- 7:40 Ensuring trust with cross-signatures and web of trust
Digital Emblems: When markings are required, but you have no rattle-can
Speakers: Bill Woodcock
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=NyOhQ4ONAUA
Overview
In his DEF CON 32 talk, "Digital Emblems: When markings are required, but you have no rattle-can," Bill Woodcock introduced a novel concept designed to modernize and secure the myriad physical markings mandated by international law. Addressing a fundamental challenge in an increasingly digital world, Woodcock detailed an ongoing Internet Engineering Task Force (IETF) initiative to create "digital emblems." These emblems are intended to supplement, and potentially replace, traditional physical markings that identify protected assets, regulated goods, or authorized entities under various international conventions. The core problem this work seeks to solve is the inherent limitations of physical markings in terms of verifiability, machine readability, and applicability to non-physical assets like digital data or online services.
The presentation highlighted the growing need for a standardized, cryptographically verifiable system to authenticate the status of diverse assets, from diplomatic pouches and UN peacekeepers to intellectual property and critical digital infrastructure. By leveraging established internet protocols such as DNS, DNSSEC, and DANE, digital emblems aim to provide a robust, scalable, and universally accessible method for validating these critical markings. This initiative promises to streamline international compliance, enhance supply chain security, and provide clearer legal recourse in cases of misuse or violation, fundamentally transforming how we identify and protect assets in a globalized, digitally interconnected landscape.
The talk underscored the practical difficulties faced by customs agents and other validators who currently contend with a "proliferation of proprietary scanners" – a fragmented and inefficient approach to verifying physical markings. Digital emblems offer a unified, open-standard solution, moving beyond the limitations of hot metal brands and stenciled signs to a system capable of marking everything from a physical ISO container to an email server, all while providing strong cryptographic assurances of authenticity and integrity.
Background
▶ Watch: Introduction to digital emblems and physical marking examples (0:00)
The necessity for standardized markings on physical objects is deeply embedded in international law and practice. Woodcock provided numerous examples, illustrating the breadth of these requirements: the ISO container markings with their serial numbers and standardized information; the UN blue helmets recognized under the Geneva Conventions for peacekeepers; the specific markings for chemical weapons components or radioactive materials crossing international borders; the UNESCO shield for world heritage sites; and the diplomatic pouch governed by the Vienna Convention of 1961 on Diplomatic Relations, which dictates its immunity from inspection or delay. A particularly detailed example was the phytosanitary marking on wood crates and pallets, mandated by the International Standard for Phytosanitary Measures number 15 under the International Plant Protection Convention, administered by the Food and Agriculture Organization. These markings typically include country codes, region codes, treatment provider license numbers, treatment methods, and serialization.
Despite their legal importance, physical markings suffer from significant drawbacks. Firstly, their authenticity and continued validity are notoriously difficult to ascertain. It’s challenging to determine if a marker was authorized to apply the mark, if the mark still applies, or if it has been tampered with or scraped off. This makes misuse hard to detect and reduces trust. Secondly, while designed for human recognition, most physical markings are not optimized for machine readability. This necessitates manual inspection or, increasingly, the use of specialized, often proprietary, scanning devices.
This leads to the "most pressing problem" identified by Woodcock: the proliferation of proprietary scanners. Customs agents, for instance, are accumulating a growing collection of single-purpose scanners, each tied to a specific type of marking or organization. This creates an inefficient, cumbersome, and error-prone validation process, requiring agents to identify the correct scanner, ensure its battery is charged, and then physically scan an item. This problem is exacerbated by major corporations like Apple, Cisco, and Nokia, which are heavily invested in combating counterfeit goods and rely on international laws administered by bodies like WIPO (World Intellectual Property Organization), which oversees some 38 international laws related to counterfeiting. These companies often develop their own proprietary systems to track and verify their products, further contributing to the fragmented landscape.
Finally, physical markings are inherently limited to physical objects. They cannot be applied to digital data (at rest or in flight) or electronic services (like email servers or websites). An attacker operating over a network cannot see a physical stencil. This leaves a vast and growing domain of assets unprotected by the traditional mechanisms of international law and compliance, creating a critical gap in security and accountability.
Key Findings
▶ Watch: Inherent problems and limitations of physical markings (3:06)
The central finding and contribution of this IETF work is the definition and architecture of digital emblems. A digital emblem is conceived as a standardized, machine-readable, and cryptographically verifiable digital counterpart to existing physical markings. Its primary purpose is to establish a robust, trustworthy binding between an issuer (e.g., a government, an international organization, a corporation), an emblem (the digital representation of a specific status or protection), and an asset (the item, person, place, or service being marked).
The digital emblem framework directly addresses the shortcomings of physical markings by offering:
- Machine Readability and Verifiability: Unlike physical marks, digital emblems are designed from the ground up for automated parsing and validation, eliminating the need for proprietary scanners.
- Cryptographic Assurance: Each emblem includes cryptographic signatures, providing strong guarantees of authenticity and integrity, making misuse and counterfeiting significantly harder to perpetrate and detect.
- Applicability to Digital Assets: Digital emblems can be attached to non-physical entities, such as digital data in transit or at rest, and online services (e.g., a website, an email server), extending the reach of internationally recognized protections and compliance.
- Dynamic Control: Emblems incorporate temporal and spatial scopes of validity, allowing issuers to control precisely when and where an emblem is considered legitimate, and enabling revocation when necessary.
- Web of Trust: The inclusion of third-party signatures enables a distributed web of trust, similar to PGP, allowing validators to trust emblems issued by unfamiliar entities based on endorsements from recognized authorities.
Ultimately, digital emblems aim to standardize the digitization of legally mandated markings, moving from a fragmented, manual, and often proprietary landscape to an interoperable, secure, and globally accessible system built on open internet standards.
Technical Deep Dive
▶ Watch: Addressing the problem of proprietary scanners at borders (4:40)
The technical architecture of digital emblems is strategically built upon existing, widely deployed, and cryptographically robust internet protocols: DNS (Domain Name System), DNSSEC (DNS Security Extensions), and DANE (DNS-based Authentication of Named Entities). This foundational choice ensures global scalability, decentralization, and leverages established trust models. Woodcock emphasized that the implementers are "doing it on top of DNS" using "existing record types almost exclusively," rather than inventing entirely new infrastructure.
At its core, a digital emblem is a set of records accessible via a DNS label. Similar to how a web browser resolves a URL to an IP address, a validator queries a specific DNS label associated with an asset. This query retrieves the emblem data, which is then cryptographically validated.
A digital emblem comprises several critical components:
- Visual Representation: This is the graphical image associated with the emblem, such as a national seal (e.g., Cote d'Ivoire's national seal for a diplomatic pouch) or an organizational logo (e.g., UNESCO's blue and white shield). While the emblem itself is digital, this provides a human-recognizable element.
- Identification of Law: A clear reference to the international or national law mandating the marking. For instance, for a diplomatic pouch, this would be the "Vienna Convention of diplomatic relations 1961." This provides the legal context and authority behind the emblem.
- Contact Information: Details for the logistics or administrative personnel responsible for the asset or emblem. In the case of a diplomatic pouch, this could be the logistics contact in the foreign ministry. This facilitates real-world verification and dispute resolution.
- Handling Flags: Specific instructions or conditions related to the asset, such as "fragile," "needs to be in pressurized compartment," or "what to do if handling conditions are violated." These flags provide critical operational guidance.
- Issuer's Cryptographic Signature: This is fundamental to the emblem's security. The issuer (the entity authorized to apply the emblem) digitally signs the emblem data using DNSSEC. This signature provides undeniable proof of the emblem's origin and ensures its integrity, meaning it has not been tampered with since issuance.
- Third-Party Signatures (Web of Trust): To enhance trust, especially for validators unfamiliar with a specific issuer, digital emblems can include cross-signatures from other recognized entities. Woodcock likened this to PGP's web of trust. For example, a customs agent might not recognize Cote d'Ivoire's foreign ministry but could trust its diplomatic pouch emblem if it also carried signatures from the foreign ministries of Guinea, Gambia, and Niger, all of whom are recognized and trusted by the validator. This mechanism significantly strengthens the global trustworthiness of emblems.
- Temporal and Spatial Scope of Validity: Digital emblems can specify precise conditions for their validity. A temporal scope defines the period during which the emblem is active (e.g., "valid from YYYY-MM-DD to YYYY-MM-DD"). A spatial scope defines the geographic area or location where the emblem applies (e.g., "valid only within this country" or "valid along this specific transit route"). This dynamic control allows for revocation, expiration, and precise application, preventing emblems from being misused outside their authorized context.
The "assets" that can be marked by digital emblems are broadly defined to encompass "people, places, things, data at rest, data in flight, and online services." This comprehensive definition ensures the framework's versatility across both the physical and digital domains, addressing the limitations of traditional markings. The delivery mechanism is straightforward: a DNS lookup of a specific label associated with the asset retrieves the emblem's data, which is then cryptographically evaluated for authenticity, integrity, and validity.
It's crucial to understand the "non-goals" of digital emblems. Woodcock explicitly stated that these emblems are not designed to provide physical protection or prevent attacks. A UNESCO emblem on a church in Ukraine does not prevent it from being bombed, nor does a digital emblem on a website prevent a DDoS attack. Instead, their purpose is to provide legal and evidentiary proof. They make the job of a lawyer in The Hague easier by demonstrating that an individual was "duly informed that what they were doing was or about to do was a war crime before they did it and did it knowingly and maliciously." Similarly, for compliance, they make the job of a customs inspector easier by providing clear, verifiable information, rather than physically shielding the asset.
Demo / Proof of Concept
▶ Watch: Diagram of digital emblem components: issuer, asset, validator (6:04)
The talk by Bill Woodcock focused on the conceptual framework and the ongoing standardization efforts within the Internet Engineering Task Force (IETF) for digital emblems. While the presentation thoroughly described the proposed architecture, its reliance on existing protocols like DNS, DNSSEC, and DANE, and the components of a digital emblem, it did not include a live demonstration or a detailed description of a specific proof-of-concept implementation. Woodcock noted that "all the actual implementers at this point are doing it on top of DNS," suggesting active development, but no specific tool or system was showcased during the presentation. The delivery mechanism was explained as a DNS lookup, similar to a website, where a DNS label is queried to retrieve and evaluate the emblem data.
Defensive Implications
▶ Watch: Ensuring trust with cross-signatures and web of trust (7:40)
The introduction of digital emblems carries profound implications for defensive strategies across various sectors, from international trade and supply chain security to humanitarian aid and cyber defense. By providing a standardized, cryptographically verifiable, and machine-readable marking system, digital emblems empower defenders with robust tools for authentication, compliance, and legal recourse.
- Combating Counterfeit Goods and Supply Chain Security: For manufacturers like Apple, Cisco, and Nokia, who are significantly impacted by counterfeit products and have international law (e.g., WIPO treaties) on their side, digital emblems offer a game-changing solution. Instead of proprietary scanners, customs agents and supply chain partners can use a single, open-standard mechanism to instantly verify the authenticity of goods. This drastically improves the efficiency of detecting counterfeit items, reducing economic losses, and enhancing brand integrity. The ability to revoke compromised emblems or specify their temporal/spatial validity adds dynamic control, further securing the supply chain.
- Streamlining International Compliance and Logistics: Digital emblems eliminate the "proliferation of proprietary scanners" that currently plague customs and logistics operations. Whether it's verifying phytosanitary measures for wood pallets, confirming the status of hazardous materials, or authenticating diplomatic pouches, a universal DNS-based lookup simplifies and accelerates validation processes. This reduces delays, operational costs, and the potential for human error, making international trade and transport more efficient and secure.
- Enhancing Legal Accountability for International Law Violations: One of the most significant defensive implications is the strengthened ability to prosecute violations of international law, including war crimes. As Woodcock emphasized, digital emblems do not physically protect assets like UNESCO world heritage sites or UN peacekeepers. However, by providing irrefutable, cryptographically signed proof that an asset was duly marked with a protected status, they make the job of a lawyer in The Hague considerably easier. This digital evidence can clearly demonstrate that perpetrators were "duly informed" of an asset's protected status and acted "knowingly and maliciously," thereby lowering the bar for successful prosecution and potentially serving as a deterrent.
- Securing Digital Assets and Services: Crucially, digital emblems extend protective markings to the non-physical realm. For the first time, digital data (at rest or in transit) and online services (like web servers or email infrastructure) can carry verifiable emblems. This opens new avenues for signaling the protected status of critical digital infrastructure, data protected under specific privacy laws, or electronic communications subject to diplomatic immunity. While an emblem won't stop a DDoS attack, it can provide forensic evidence of the attack's nature and the protected status of the target, aiding in attribution and legal action.
- Building Trust Through a Web of Trust: The inclusion of third-party signatures allows for the creation of a distributed web of trust. This is a powerful defensive mechanism against impersonation and phishing. If a validator encounters an emblem from an unknown issuer, cross-signatures from trusted entities provide a chain of trust, assuring the validator of the emblem's legitimacy. This helps in validating entities and assets in complex, multi-party international contexts where direct trust relationships might not always exist.
- Detecting Misuse and Tampering: The cryptographic signatures inherent in digital emblems make it virtually impossible to affix an emblem to an unauthorized asset, display it in an incorrect time or place, or tamper with its contents without detection. Any alteration would invalidate the signature, immediately flagging the emblem as fraudulent. This drastically improves the ability to detect and prevent misuse compared to physical markings, which can be easily forged or altered.
In essence, digital emblems provide a standardized, robust, and verifiable layer of metadata for assets, enabling a proactive and evidentiary defense posture against fraud, non-compliance, and violations of international law across both the physical and digital worlds.
Key Takeaways
- Standardization of Markings: Digital emblems aim to standardize and digitize the diverse physical markings required by international law, replacing disparate, often proprietary, verification methods with an open, interoperable system.
- Leveraging Existing Internet Infrastructure: The framework is built upon the robust and globally deployed DNS, DNSSEC, and DANE protocols, ensuring scalability, security, and broad applicability without requiring new infrastructure.
- Addressing Physical Marking Limitations: Digital emblems overcome critical issues with physical markings, such as difficulty in detecting misuse, lack of machine readability, vulnerability to wear/vandalism, and inability to mark non-physical assets like digital data or online services.
- Cryptographic Verifiability and Trust: Each emblem incorporates the issuer's cryptographic signature and supports third-party cross-signatures (a web of trust), providing strong assurance of authenticity, integrity, and preventing unauthorized application or tampering.
- Enhanced Compliance and Legal Enforcement: While not offering physical protection, digital emblems significantly ease the burden of compliance for customs and logistics, and provide crucial, verifiable evidence for prosecuting violations of international law, including war crimes and counterfeiting.
- Dynamic Control and Broad Applicability: Emblems include temporal and spatial validity scopes, allowing for precise control and revocation. They can mark a wide range of "assets," including people, places, things, digital data, and online services, extending their utility across both physical and digital domains.
About the Speaker(s)
Bill Woodcock is a key figure involved in the development of the digital emblems standard within the Internet Engineering Task Force (IETF). His presentation at DEF CON 32 served as a report on this ongoing IETF work, demonstrating his expertise in internet standards and infrastructure, particularly concerning the practical application of DNS, DNSSEC, and DANE for real-world problems.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Bill Woodcock's talk on "Digital Emblems" introduces a critical IETF initiative to standardize and digitize the myriad physical markings required by international law. By leveraging established protocols like DNS, DNSSEC, and DANE, this framework aims to provide cryptographically verifiable, machine-readable emblems for everything from diplomatic pouches to digital data. It directly addresses the inefficiencies of proprietary scanners and the inability to mark digital assets, offering profound implications for international compliance, supply chain security, and legal accountability, including the prosecution of war crimes.
Heather Calloway (CISO) — STRONG ACCEPT
Bill Woodcock's exposition on Digital Emblems at DEF CON 32 presents a critical advancement in how institutions manage accountability and risk across physical and digital domains. By leveraging established internet protocols, this IETF initiative offers a standardized, cryptographically verifiable framework to replace antiquated physical markings, directly addressing challenges in supply chain security, international compliance, and legal enforcement. While still in standardization, the strategic implications for governance and verifiable evidence are substantial for any CISO operating in a globalized environment.