WSIS Forum 2026
AI-generated report

Building Trust and Protection for Essential Digital Services: From Standards to Deployment

6 speakers
Summary

This discussion, moderated by Joelle Rizk, focused on the Digital Emblem Project led by the International Committee of the Red Cross (ICRC), which aims to translate the protective signalling function of physical emblems such as the Red Cross into the digital domain . The project addresses a critical gap: whilst medical services and humanitarian organisations have used distinctive emblems for over 150 years to signal their protected status under international humanitarian law (IHL), no equivalent mechanism exists to identify and protect their digital infrastructure during armed conflict .

From a legal perspective, Samit D'Cunha explained that the obligation to respect and protect medical services dates back to the first Geneva Convention of 1864, and that this protection has never been limited to the physical domain . He noted that a 2024 resolution adopted at the International Conference of the Red Cross and Red Crescent, involving 196 states party to the Geneva Conventions, explicitly affirmed that this obligation applies to the use of ICTs . Crucially, no new legal protection needs to be created, as existing IHL obligations already cover interference through cyberspace .

On the technical side, Mauro Vignati described a prototype called ADEM, developed with ETH Zurich, which uses existing technologies such as the Domain Name System (DNS) to distribute and verify the emblem . The prototype's code is publicly available on GitHub, and testing has already begun with national societies including the British Red Cross and Australian Red Cross . Tommy Jensen emphasised that standardisation through bodies such as the IETF is essential for interoperability, security, and for enabling industry to develop accessible, out-of-the-box deployment solutions .

Emma Cunliffe of Blue Shield International highlighted a parallel effort to apply a digital emblem to protected cultural heritage, noting that UNESCO member states recently approved guidelines recommending its use . She cautioned that significant challenges remain, including insufficient national legislation, under-resourcing of the heritage sector, and low technical capacity in many countries .

An audience question raised concerns about unequal technical capacity across countries, particularly in developing nations . Panellists agreed that the solution must function in severely constrained network environments and that a cascading model of capacity-building through national societies and international partners would be essential . The discussion concluded that the Digital Emblem Project, whilst technically and legally complex, serves the straightforward purpose of making IHL protections visible, detectable, and verifiable in cyber operations during armed conflict .

Keypoints
  • Overall Purpose

  • The discussion centres on the ICRC's Digital Emblem Project, which aims to translate the long-established physical protective emblems of international humanitarian law (the Red Cross, Red Crescent, and Red Crystal) into the digital domain. The session brings together legal, technical, and operational experts to explain the project's rationale, its current prototype stage, and the steps needed to achieve practical, global deployment.
  • --
  • Major Discussion Points

  • The legal basis and necessity of a digital emblem: International humanitarian law, dating back to the first Geneva Convention of 1864, obliges warring parties to respect and protect medical services and humanitarian operations. As conflict increasingly involves cyber operations, and as medical and humanitarian organisations depend on digital infrastructure, there is currently no recognised means of signalling these protections in the digital domain. A 2024 International Conference resolution (Resolution 2, Operative Paragraphs 6 and 7) confirmed that the obligation to respect and protect applies to the use of ICTs, providing a clear legal foundation for the project without requiring the creation of new categories of protection.
  • Technical standards and the prototype (ADEM): The digital emblem relies on existing, widely adopted internet technologies - notably the Domain Name System (DNS) and WebPKI - rather than reinventing infrastructure. Standardisation is essential so that all actors, regardless of origin, speak the same technological language and can interoperate reliably. The current prototype, called ADEM, was developed with ETH Zurich, is publicly available on GitHub, and is already being tested by national societies including the British Red Cross and Australian Red Cross. Standardisation work is ongoing at both the IETF and the ITU. - The role of industry and the importance of marketing the solution as a product: Technical standards alone are insufficient if deployment requires specialist expertise. Industry's critical role is to translate standardised protocols into accessible, out-of-the-box solutions that can be used by medical personnel or heritage professionals without requiring deep technical knowledge. This is particularly important given that many potential users - especially in the cultural heritage sector - operate with limited resources and outdated technology. - Parallel experience from the Blue Shield and cultural heritage protection: The Blue Shield emblem, established under the 1954 Hague Convention, offers a parallel case study in extending physical protective emblems to the digital domain. Digital cultural heritage - including records of destroyed sites such as Palmyra - now requires the same protections as physical artefacts. However, the Blue Shield faces significant challenges: fewer than 10 countries have enacted legislation on the emblem, awareness remains low, and the heritage sector is severely under-resourced technologically. A major step forward was achieved when UNESCO member states approved guidelines recommending the use and implementation of the digital emblem. - Capacity building and inclusivity across diverse contexts: A recurring concern raised both by panellists and an audience member is ensuring the digital emblem works in highly constrained environments, such as areas limited to 2G connectivity. Testing must reflect the full diversity of national societies across all regions, not only well-resourced ones. A cascading model is envisaged, whereby major actors assist others in deployment, supported by national societies acting as regional champions, international bodies such as UNESCO, and heritage funding organisations.
  • --
  • Overall Tone

  • The overall tone of the discussion is constructive, collaborative, and cautiously optimistic. Speakers consistently frame the project as a shared endeavour involving legal experts, technologists, civil society, and states, with a clear humanitarian purpose. There is a sense of measured excitement, particularly around the launch of Phase 2, and the ADEM prototype was demonstrated the previous day. When the audience question raises concerns about capacity gaps in developing countries, the tone becomes more sober and reflective, with panellists openly acknowledging the challenges of inclusivity and under-resourcing. However, the discussion closes on a hopeful note, with the moderator reaffirming the life-or-death stakes of the project and the panel expressing confidence that the combination of legal norms and technical standards can ultimately deliver meaningful protection.
Speakers Overview
SD
Samit D'Cunha
189 wpm · 10 min
MV
Mauro Vignati
145 wpm · 4 min
TJ
Tommy Jensen
146 wpm · 5 min
EC
Emma Cunliffe
186 wpm · 8 min
JR
Joelle Rizk
143 wpm · 13 min
A
Audience
156 wpm · 1 min

Digital Emblem: Building Trust and Protection for Essential Services - Expanded Summary

#

Session Overview and Context

The session, moderated by Joelle Rizk, brought together legal, technical, and operational experts to discuss the Digital Emblem Project led by the International Committee of the Red Cross (ICRC) . The panel comprised Samit D'Cunha, legal and policy lead on the Digital Emblem Project at the ICRC; Mauro Vignati, the ICRC's technology advisor and technical lead on the project, joining online; Emma Cunliffe, Head of Operations at Blue Shield International; and Tommy Jensen, a product manager at Cloudflare and former inaugural chair of the Digital Emblem Working Group at the IETF . The session took place one day after a significant milestone: the launch of Phase 2 of the Digital Emblem Project at CERN, where a prototype was demonstrated to ICRC colleagues, industry stakeholders, and others . Phase 2 represents a transition from conceptual development and stakeholder consultation to prototype testing and technical demonstration .

#

The Legal and Historical Basis for a Digital Emblem

D'Cunha opened the substantive discussion by tracing the origins of the physical emblem system to the first Geneva Convention of 1864, which established specific protections for medical services in armed conflict and created the obligation to "respect and protect" those services . He explained that even then, it was understood that these protections required a means of identification in complex security environments, which led to the creation of the Red Cross emblem and, subsequently, the Red Crescent and Red Crystal . Over time, the use of the emblem evolved from armbands to vehicles and hospital rooftops, reflecting the changing nature of conflict and humanitarian operations .

A crucial historical precedent was established in the 1970s, when it was recognised that visual confirmation of an emblem was no longer sufficient . Working through the International Telecommunication Union (ITU) and the International Civil Aviation Organization (ICAO), electromagnetic and light frequency signals were standardised as additional means of identifying protected entities in armed conflict . These standards were directly incorporated into international humanitarian law (IHL) through Annex I of Additional Protocol I to the Geneva Conventions . This precedent is significant because it demonstrates that the international community has already successfully translated physical emblems into technological signals once before, lending the Digital Emblem Project both legal legitimacy and historical continuity.

D'Cunha then explained the contemporary gap that the project seeks to address: cyber operations are now a reality of armed conflict, and medical services and humanitarian organisations such as the ICRC depend on digital infrastructure, yet there is currently no recognised means of signalling their legal protection in the digital domain . Joelle Rizk reinforced this framing, noting that conflict is no longer waged solely with airstrikes and artillery but also through digital means, raising the question of how the protective signalling function of physical emblems can be translated to the digital domain .

#

Navigating Legal Uncertainty: Existing Protections and Broad Consensus

A particularly important exchange addressed the apparent tension between the Digital Emblem Project and the broader lack of consensus among states on how IHL applies to cyberspace. Joelle Rizk asked how the project could proceed when there is still no broad agreement on questions such as the definition of a "cyber attack" or whether data constitutes an "object" under IHL . D'Cunha acknowledged this diversity of views but argued that it does not undermine the project's legal foundation . He pointed out that the specific obligation to respect and protect medical services is a settled area of IHL, and that a party to a conflict which deletes patient data or interferes with medical equipment through a cyber operation is clearly in violation of that obligation, regardless of contested definitional questions .

D'Cunha cited substantial evidence of broad state consensus on this specific point: over a dozen individual state positions, the common European Union position, and the common African position all affirm the obligation to respect and protect medical services and humanitarian personnel in the context of ICTs . Most significantly, Resolution 2 was adopted at the 2024 International Conference of the Red Cross and Red Crescent, which brings together all 196 states party to the Geneva Conventions as well as 193 components of the Red Cross and Red Crescent movement - comprising the ICRC, the International Federation, and 191 national societies - and explicitly affirmed in Operative Paragraphs 6 and 7 that this obligation applies to the use of ICTs, for both medical services and humanitarian personnel respectively . This broad consensus provides a solid legal foundation for the project without requiring the creation of new legal categories or protections .

D'Cunha was equally clear that no new legal protection needs to be created, because the existing obligation is already broad and unqualified, covering all domains - physical, aerial, maritime, outer space, and cyberspace . The Digital Emblem's purpose is therefore not legal innovation but rather making existing protections visible, detectable, and verifiable in the digital domain .

#

Technical Architecture: Building on Existing Infrastructure

Mauro Vignati addressed the technical dimensions of the project, emphasising that the digital emblem is not reinventing the wheel but rather reusing technologies already widely adopted on the internet, including WebPKI and the Domain Name System (DNS) . He explained that standardisation is essential because all actors, regardless of their region or country, must speak the same technological language to enable consistent and reliable interaction with the digital emblem . The DNS was selected as the first protocol for distributing the emblem because it is universally used for everyday internet activities such as email and web browsing, making it a natural and accessible foundation .

Vignati described the current prototype, called ADEM (Authenticated Digital EMblem), developed in collaboration with ETH Zurich . Rizk clarified for those attending online or reading the transcript that ADEM is the name of the prototype, and offered to have Vignati share both the GitHub repository link and the verification tool link in the session chat . Vignati confirmed he would share these links, noting that the prototype's code is publicly available on GitHub for inspection and use by anyone, and that a public verification tool has been deployed online . Vignati clarified that ADEM is not the final version of the digital emblem, as standardisation work is still ongoing at both the IETF and the ITU . The prototype has been submitted to these bodies, and testing is already underway with national societies, with the British Red Cross and Australian Red Cross having successfully implemented the emblem on their domains . D'Cunha noted that eight national societies are currently involved in testing the digital emblem . Vignati outlined the next steps as finalising standardisation, reaching broad agreement on the technology, and then deploying the emblem to authorised entities .

#

The Role of Technical Standardisation and Industry

Tommy Jensen provided a broader perspective on why standardisation through bodies such as the IETF is indispensable. He described the Digital Emblem as "probably the best example I've ever seen of a need for interoperability," arguing that without standardised protocols, parties on different sides of a conflict would need to manually invent bespoke signalling arrangements - a practically unworkable requirement . Standards eliminate this problem by providing a single, universally recognised solution that all parties can rely upon . He also noted that the Tallinn Manual states that parties need to signal protections to each other, which might seem like a solved problem, but that in practice this is far more difficult to achieve than simply stating the requirement .

Jensen further argued that standardisation enables private industry to develop product-type solutions that can be deployed out of the box, with predictable patterns and good documentation, making the emblem accessible to all . Crucially, bringing the standard to expert bodies like the IETF allows specialists across fields to identify and address flaws before deployment, improving the robustness and security of the system . He expressed confidence in the prototype while noting that expert scrutiny would refine it further in ways that would benefit everyone for the decades to come .

On the question of industry's role, Jensen offered a vivid operational illustration: if medical personnel must become experts in computer networking in order to remove a digital emblem from an asset as ground is being surrendered to an incoming force, the problem has not been operationally solved . Industry's critical contribution is therefore to translate standardised protocols into accessible, out-of-the-box solutions that non-technical users can deploy and manage without specialist knowledge . This point about making solutions accessible and deployable without specialist knowledge was echoed by Cunliffe from the heritage sector perspective, connecting the technical and operational dimensions of the project.

#

The Blue Shield and Cultural Heritage: A Parallel Framework

Emma Cunliffe of Blue Shield International introduced a parallel dimension to the discussion, explaining that the Blue Shield emblem was established under the 1954 Hague Convention for the Protection of Cultural Property in the Event of Armed Conflict, which specifies a blue and white shield to be placed on cultural items of great importance to signal their protection . She noted that the cultural sector has advanced significantly in its use of digital technologies, and that some cultural heritage - including records of destroyed sites such as Palmyra and the Berlin Wall - now exists only in digital form, requiring the same protections as physical artefacts .

Cunliffe described a significant recent policy milestone: UNESCO member states approved guidelines that include recommendations for the use and implementation of the digital emblem for cultural heritage protection . She also noted that Blue Shield International had produced a substantial report, to be launched shortly, examining the use and practice of Blue Shields in detail, including digital heritage and recommendations to promote the digital emblem. However, she cautioned that significant challenges remain. Despite nearly 140 states having signed the Hague Convention, the Blue Shield emblem is poorly understood and inconsistently implemented, with fewer than 10 countries found to have legislated it in spot checks, and only around 40 to 50 states actually placing Blue Shields on monuments . The study also found a number of cases of misuse of the emblem, which Cunliffe noted appeared to be unintentional, underscoring the need for clear national legislation and reporting mechanisms. She argued that national legislation is essential to define digital heritage, formally recognise the emblem, establish systems for reporting misuse, and build the trust necessary for the emblem to function effectively . She contrasted this with the Red Cross emblem, which is legislated in almost every country in the world .

Cunliffe also highlighted a structural barrier to deployment in the heritage sector: it is severely under-resourced, often relies on outdated technology, and has very low technical know-how outside major institutions . She expressed enthusiasm for standardised, out-of-the-box solutions that could help people who would not otherwise understand how to apply technical protections , independently arriving at the same conclusion as Jensen from a very different institutional perspective. She noted that the timing of the digital emblem's development is opportune, framing it as an opportunity rather than a burden: the emblem can be implemented in parallel with the physical emblem, allowing both to be introduced together rather than sequentially .

#

Capacity Building, Inclusivity, and the Digital Divide

An audience member, Janine, raised a pointed challenge about the unequal capacity of different countries to implement the proposed solutions, noting that even in developed countries the capacity is not uniform, and that the situation is considerably worse in developing countries and conflict zones . This question prompted the most substantive and candid responses of the session.

D'Cunha acknowledged the challenge and noted that the first Geneva Convention was itself a predominantly European instrument, signed by only 12 states, most of them European . He emphasised that over 160 years, the Geneva Conventions have achieved universal ratification, and that the same commitment to universality must inform the Digital Emblem Project . He referenced Paragraph 12 of Resolution 2 of the 2024 International Conference, which calls on states to provide capacity building to those that need it, and identified national societies as essential partners in building state capacity . He also acknowledged that current testing is concentrated among well-resourced societies and stressed the need to expand it to societies in Asia, Africa, and South America .

Jensen addressed the technical design implications directly, citing a presentation at the IETF noting that infrastructure in Palestine was at one point limited to 2G cellular connectivity . He argued unequivocally that designing for better connectivity and thereby excluding parties is a non-starter, and that the emblem must be readily deployable anywhere by anyone . This introduced a firm technical design requirement - performance under severely constrained networking conditions - that had not been explicitly articulated earlier in the session. Vignati described a cascading knowledge-sharing model, whereby major actors such as the British and Australian Red Cross help others implement the emblem, spreading technical capability across the movement . Cunliffe described a multi-partner approach involving civil society, NGOs, governments, international agencies such as UNESCO, and major heritage funding bodies as the only way to achieve the necessary scale . She illustrated the severity of the connectivity challenge in the heritage sector with a concrete example: a national committee president having to drive two hours simply to download a file, underscoring how acute the digital divide remains for many heritage institutions.

#

Unresolved Issues and the Path Forward

Despite the broadly optimistic tone of the discussion, several significant challenges remain unresolved. The diversity of state views on how IHL applies to cyber operations more broadly - including contested definitions of "attack" and whether data constitutes an "object" - creates an uncertain legal environment surrounding the digital emblem, even if the specific protection of medical services is broadly agreed . The question of equitable implementation across countries with vastly different digital infrastructure capacities was acknowledged but not fully resolved, with the cascading model representing an important approach that will require further development . The Blue Shield emblem's absence from national legislation in most countries, and the lack of a shared definition of digital cultural heritage, leave significant gaps in the legal foundation needed to prevent misuse . The heritage sector's severe under-resourcing and reliance on outdated technology present a practical barrier that will require coordinated multi-partner efforts to address .

#

Closing Remarks

Joelle Rizk closed the session by underscoring the life-or-death stakes of the project: a cyberattack on a medical service during armed conflict could cost civilian lives, and an attack on a humanitarian organisation's database could obstruct critical protection services such as tracing missing persons . She characterised the Digital Emblem Project as technically and legally complex but serving a straightforward purpose - making IHL protections visible, detectable, and verifiable in cyber operations during armed conflict - and as an ambitious endeavour that combines legal norms with technical standards . The session as a whole demonstrated that the project enjoys broad cross-sectoral support, with legal, technical, cultural heritage, and industry perspectives converging on the same core principles, even as significant practical and operational challenges remain to be addressed on the path to global deployment.

Joelle Rizk
today on this session where we will be discussing the digital emblem, building trust and protection for essential services. I apologize for the date. There's been just a bit of an overlap and a technical challenge that we faced. So without further ado, we can get started. We have one speaker with us joining online and three speakers here in physical presence. So ladies and gentlemen, about a year ago, we were all here together discussing the digital emblem. Recording in progress. A project that is led by the International Committee of... The Red Cross. A year later, we were discussing the digital emblem and gathering support and opinions from states and other stakeholders, including national societies and states. However, this year, actually yesterday, I've had the pleasure to be present with ICRC colleagues, industry stakeholders, and others at CERN to launch Phase 2 of the digital emblem project, which is basically moving from discussions around formulation and elaboration and development of this project to a phase where a prototype of the digital emblem was tested, was demonstrated, with also a demo of the digital emblem. Of course, we wish everyone here could also have been there with us yesterday, but we will take the chance today with the experts. To talk about this Phase 2, to discuss testing and tech solutions that are being developed for the digital emblem. So you hear me saying a lot about the digital emblem, but maybe I should take a step back and actually speak a little bit more about what the digital emblem is and why it is there. So over 150 years, armed forces, medical services, and authorized civilian medical services, and certain humanitarian organizations have been using distinctive emblems, symbols, to signal to warring parties that they are actually having a function of medical service or a humanitarian service. And therefore, they have a certain protection. Under international humanitarian law. Now, the use of this emblem means that this entity that is authorized to use the emblem is saying to anyone who is conducting a military operation, I am an entity that I'm conducting, and I am conducted, that is protected under international law, and I conduct, I have a humanitarian function, or I have a medical function, and therefore, I am not a legitimate military target. So, these emblems or these symbols are the Red Cross, the Red Crescent, and the Red Crystal, and they're universally accepted and recognized symbols, and they have global recognition by states as well as non -state actors. But today, in the world of ICTs, in the digital age where conflict is not only waged with airstrikes and artillery, it's also waged with digital means, digitalized conflict. As part of conflict are digital operations, whether they are cyber operations or other. How can we translate this signaling of these protections under international law to the digital domain? The answer to that question was, already a few years ago, a digital emblem. Is it a signal? What is it? Is it a sign? How is it visible? Is it verifiable? Is it authentic? How can it be standardized? This is what the ICRC has been working on for the past few years with states, with industry actors, with technical experts, with national societies as well to answer these questions and to develop such standards and technical solutions. So, I don't want you to hear more from me. I want you to hear from the people who are actually working on this project. So, today we ask, how can this mark, emblem, or symbol, or entity maybe, how can it signal these protections under international humanitarian law in the digital domain? I will turn to my colleagues to answer these questions. Let me quickly introduce them. With us today is Simit Takunya. He's a legal advisor at the International Committee of the Red Cross, and he's the legal lead on the Digital Emblem Project and the policy lead of the Digital Emblem Project. Online, we have Mauro Vignati, also at the International Committee of the Red Cross, and he is the technology advisor at the ICRC and the technical lead of the Digital Emblem Project. On my left here is Emma Cundith, who is the head of the operations of the Blue Shield International, supporting the Blue Shield movement, which is an association of NGOs dedicated to protecting cultural heritage in conflict and disaster. And last but not least, Tommy Jensen, who is on my right here, is a product manager at CloudFare, and he has volunteered extensively at the IETF with various functions. including various technical aspects of developing the Digital Emblems. And I have to say, he's very humble. He doesn't say it in his biography, but he was also the first chair of the Digital Emblem Working Group. So, guys, let's get through the substance quickly. Samir, let me start with you. From a legal perspective, what is the problem, what is the dilemma that the Digital Emblem Project is trying to solve?
Samit D'Cunha
Sure. Thanks so much for that question, Joelle. I think it's a good opportunity to sort of, you know, take a step back and start with, well, you know, why is there this Digital Emblem Project to begin with? You know, what is it trying to identify? And to understand the Digital Emblem, we have to understand sort of the thinking behind, well, why is there a Red Cross emblem? Why is there this physical emblem? To understand that, we do, you know, we go back to what Joelle was saying earlier. We go back to, you know, the signing of the very first Geneva Convention in 1864. One of the main things that this convention did was it created something that we call specific protections for the medical services and eventually certain humanitarian operations as well. And those specific protections designed to, of course, protect the medical services in times of armed conflict. known as, you know, the language of that protection is the obligation to respect and protect. And it was already understood then in the 1860s that if you're going to have a way, you know, if you're going to have these specific protections for the medical services and for humanitarian activities, well, there has to be a way to identify them in complex, you know, security environments like armed conflict. And so already then it was, you know, understood that, well, there needs to be a way to signal this, there needs to be an emblem. And that's really what led to the creation of the Red Cross emblem and eventually also the Red Crescent and Red Crystal. So over time, of course, the use of that emblem evolved, right? So initially it was really a Red Cross on a white armband. Eventually it was also used on vehicles, so a Red Cross on a white background on a vehicle, on the roofs of hospitals. And, you know, as conflict evolved and as the medical services and humanitarian activities evolved, well, the placement and use of the emblem evolved. Then in the 1970s. It was understood that we could no longer only rely. on a visual confirmation of an emblem. So in the 1970s, working, you know, through the ITU, as well as the International Civil Aviation Organization, something was developed called the Distinctive Signal. So electromagnetic signals, radio frequencies, so ITU -R, of course, and then ICAO, International Civil Aviation Organization, light frequencies that were standardized as the means of identifying the specific protection in situations of armed conflict. And those standards were directly incorporated into international humanitarian law. It came after the Geneva Conventions, the four Geneva Conventions, of course, as well as the additional protocols of the Geneva Conventions. So in the Annex I of Additional Protocol I, these standards from the ITU, from ICAO, are directly incorporated. And so they form part today of international humanitarian law. And then if we fast forward to today, well, you know, now we're in a new situation where cyber operations are a reality of armed conflict. The medical services depend. And on digital infrastructure, humanitarian operations. like those of the ICRC depend on digital infrastructure, but we don't have a way of identifying that protection when it comes to the protected digital infrastructure of the medical services and humanitarian activities. And so that's really sort of the legal basis for this project is how do we develop the means to identify, to signal that legal protection, that old legal protection, that 160 -year -old legal protection when
Joelle Rizk
Thank you, Sami. I will move to a question for you, Mauro, online. Just testing because we don't see you. Are you still with us?
Mauro Vignati
I am. Yeah.
Joelle Rizk
Okay, so the question for you, Mauro, is concerning the technical aspects of the digital emblem. So yesterday at this demo where we saw a prototype of the digital emblem, you all were explaining the need for, the digital emblem to be secure, to be verifiable, to be detectable. Now, what does that mean in terms of technical standards behind the digital emblem and why such technical standards are required in such a way?
Mauro Vignati
So we have to say, firstly, that we are not completely reinventing the wheel. So we are reusing technologies that are already widely adopted for several purposes on the Internet. And I'm thinking about WebPKI and other solutions that we are reusing for the digital emblem. But the very fundamental important stuff of standardizing this technology is because everyone has to talk the same technological language to be able to have the same interaction from different regions and countries. So that's why the standardization is very important. From a technology perspective, we have already... technologies that are standardized, but we have to package them in different ways, and we have to have an agreement upon what is exactly the technology that is supporting the digital emblem. That's why we started with probably the most widely used protocol for providing digital emblem, which is the DNS, the domain name system, which is the one that we use daily for our activities on the Internet by retrieving emails, by surfing the web, and so on. So we are all using this protocol. So this is why the first protocol we envisage and we are testing now to serve the emblem when it is requested is through DNS. We need agreement upon the distribution methodology, and so that's why it is very fundamental that we standardize this technology.
Joelle Rizk
Thank you, Mauro. I will, maybe if we have a little bit more time, come back to you to discuss more the need for it to be visible, verifiable, and detectable, as we saw yesterday. But let me first move to Emma. Emma, again, we were talking about the importance of parallel experiences and similar experiences in other domains. And you come from, like we were saying, Blue Shield, working on the protection of cultural property. And you have developed that Blue Shield also, if I understand correctly, as an emblem to signal that protection. So can you explain to us a little bit more on that work? And why is such a digital emblem and developing these trust mechanisms, why are they important?
Emma Cunliffe
Thank you so the blue shield emblem was has a a more recent but parallel history to the red cross it exists in another area of international humanitarian law called the hague convention for the protection of cultural property in the event of the arms conflict which dates to 1954 and has two protocols and it specifies a blue and white shield that can be used to place on cultural items that are of great importance to people to make sure that like the people who value them they are also protected during conflicts and the thing and and the cultural sector is the same uh it has moved it has advanced we now have a lot of cultural information the records in the archives the famous sites museum collections that are stored digitally but also there are whole areas now of cultural heritage that only exist online records of sites like like the destroyed areas of palmyra or like the Berlin Wall that don't exist anymore and they only exist in these digital forms and so we've been really excited to work and work with and learn from the ICRC to understand how actually we might also adopt a digital emblem to be able to say these things are also protected because I think it's very easy for people they can maybe conceptualize medical records but actually to say well this museum that is the history and the identity of our people actually its records are protected these sites and the records of these events that are critical in our identity and who we are they are protected and they have the same protections as the more physical
Joelle Rizk
Tommy, thank you Emma. Tommy I come to you again with a technical standards question we're again speaking of a prototype here we're speaking of a potentially in the future a digital emblem that protects digital assets and infrastructure. now as a non -technologist i'd like to better understand the role of technical standards in moving such an idea such a great idea from being a prototype to actually being a secure and deployable technical standard can you explain to us a little bit the why and the how of the importance of such technical standards.
Tommy Jensen
Certainly this problem of needing to be able to signal the existence of protections on a given on a given asset is probably the best example i've ever seen of a need for interoperability because because of the the implications of not being able to organizations like the ietf allow for standardization of protocols in the technical sense and not the legal sense that allow communication of computers across the internet that without we couldn't have any of the model of the ietf modern web email what have you because otherwise companies and and states each invent their own things, and then someone has to come up with a way to translate between systems. Standards are the reason that we don't have to do that, because we can all rely on one solution to a given technical problem. The importance to the digital emblem is that without that, then aggressors on different sides of a conflict would need to manually invent or define a way to signal to each other, which when I first started participating in this effort, I learned that the Talon Manual requires that, and I was like, ah, neat. It's a solved problem. But of course, in practice, that's far more difficult than just saying that that's what you need to do. When a standard exists, then, for example, private industry can provide product -type solutions to that so that things can be deployed more out of box, that there's predictable patterns, there's good documentation, that everyone knows how to display an emblem. because it's the same for everybody, which also makes it easier then to make more accessible. And so standardization is really important because it makes it interoperable. On the element of security, it's important because when you come to bodies like the IETF, there's experts across fields who can tear it apart and find flaws before it's deployed so that the standard can be refined. And the prototype is very exciting, and I think it works quite well. And as Mara was describing, the selection of technology such that there doesn't have to be a huge reinvention of how Internet routing works or anything to accomplish it. Having experts across areas be able to refine it will make it. Even better in ways we won't predict that will benefit everyone for the decades to come that this needs to work.
Joelle Rizk
Thank you Tommy Samit if I may come back to you I've asked you the easier question earlier so if I may come back to you with a bit more of a complex one do states agree today on the protective or the signaling that the digital emblem does for the protective function of it if at the same time there's still not yet an agreement a broad agreement on how IHL applies to the cyber domain how are you navigating this? How are you reconciling these issues?
Samit D'Cunha
That's a really good question Joelle so it's true of course there's a diversity of views among states on how international law applies to the use of ICTs to the cyber domain so there's different perspectives on what the meaning of attack is when it comes to cyberspace what the meaning of an object is because objects are civilian objects are protected from attack, but, you know, is data, for example, you know, can we consider data, online data, an object, you know, those are indeed questions where there's a diversity of views and there isn't one necessarily clear answer. There's the Talon Manual that takes certain positions on this, but of course, the Talon Manual is an expert manual. That being said, there are areas where there is, you know, quite clear agreement. And, you know, one of them is this obligation that I mentioned that really came from the very first Geneva Convention, this obligation to respect and protect the medical services. So, to be clear, you know, a party to a conflict that deletes patient data of a hospital or that, you know, interferes with medical equipment, the functionality of medical equipment through a cyber operation or some kind of cyber activity, this is clearly a violation of their obligation to protect the medical services. And it's not a question of whether what they did is an attack or whether, you know, that data that I, you know, the data of patient data is an object or not, that decides the point because there is this obligation in a conflict to protect the medical services. And so, of course, any kind of undue interference through a cyber activity would then be a violation of that rule. And we do see that. So in the individual positions of states, and there's, you know, over a dozen of them now that clearly state that, of course, you know, the medical services must be respected and protected. The two common positions, the common European position, European Union position, rather, and the common African position, both mention the obligation to respect and protect the medical services and humanitarian personnel. And of course, you know, in 2024, at the International Conference of the Red Cross and the Red Crescent, which brings together all states that are party to the Geneva Convention, so 196 states that are party to the Geneva Conventions, as well as all the components of the Red Cross and Red Crescent movement. So in total, 193 components, if you count the ICRC, the Federation. International Federation of the Red Cross and the Red Crescent, as well as the 191 national societies, you know, the ICRC. There's a resolution, Resolution 2, that was adopted in 2024 at this conference. And in Operative Paragraph 6 and 7, they very clearly state that the obligation to respect and protect applies, including, you know, for the medical services, including with respect to the use of ICTs. That's in Operative Paragraph 6. And in Operative Paragraph 7, that same language, but with respect to humanitarian personnel. And that brings together all the states that are party to the Geneva Convention. So, you know, that is an area where there is this broad agreement. What we're missing is a way of identifying, you know, that protection when it comes to the use of ICTs. And that's really the ethos of this project.
Joelle Rizk
So if I may, in a follow -up question, so how can we translate these existing protections you mentioned without creating new legal strategies or new categories of protection to translate those into the digital infrastructure or digital environment?
Samit D'Cunha
Yeah, no, exactly. So we don't need to create a new. We don't need to create a new protection because the protection is already there. broad and it's unqualified. So it's, you know, if you have to protect the medical services, you have to protect a hospital. It means that you, as a party to a conflict, you cannot do anything that is unduly interfering with that hospital. So, you know, that's whether that's in the physical space, through outer space, through cyberspace, from the air at sea, you cannot unduly interfere with
Joelle Rizk
Thank you, Sami. Mauro, I will come back to you online to ask again where we are right now with the project. Like I was mentioning yesterday, we saw a demo, we saw a prototype. Where do we stand today with the project and what still needs to be done so that we move to practical deployment?
Mauro Vignati
Yes, on the project from a technical perspective, we are now testing a solution that is the one that the ICRC developed together with the University ATH of Zurich. So this is not the final version of the digital, because we are still in the process of standardizing the technologies at the ITU, at the Internet Engineering Task Force, ATF. But the prototype that we submitted to the ITF and ITU, and we hope to adopt something very similar to what we are already testing, it's there, it's public, and it's also part of the transparency that we were talking before. It's already there. The code is visible and usable by everyone. It's hosted on a GitHub repository, so everyone can download and inspect this code and produce software. It's also that can generate emblems and generate a tester for the emblem. And we have also online. for the sake of the demonstration of yesterday, we also put online a verification tool of what we call ADEM, which is this prototype, and I can share the link on the chat of this meeting. So we are already working with national societies in testing this solution ADEM, so we have already the British Red Cross, the Australian Red Cross that already put this emblem on their domain and so through this verification platform that I will share everyone can test the presence of the emblem of those domains that I mentioned before and see that the emblem is correctly displayed and provided. So in a nutshell, we have a prototype, it's called ADEM we are testing this prototype and at the same time we are standardizing the technology and the next step will be to finalize the standardization, to come up with a common agreement upon the technology and then to deploy the emblem at entities that are meant to display it.
Joelle Rizk
Thank you, Mauro. Just for clarification for those online or who are reading the transcription, it's an ADEM, the name of the prototype. And Mauro, could I ask you to please put in the name of the GitHub repository on the chat as well for those that are online? Emma, I'll come back to you here and also on the subject of deployment and moving forward. You've already started seeing certain achievements in the deployment of the Blue Shield. Now, could you talk to us a little bit more about what legal or policy considerations or even operational ones that you need to work with in order to deploy such a system in
Emma Cunliffe
So although the 1954 Hague Convention is signed by almost 140 countries, it has far less implementation than the Red Cross. A lot of people still don't know what the Blue Shield even is when they see it. They have no real understanding. So there was a huge step forward yesterday when the UNESCO team who support the Hague Convention went to the member states with guidelines for the Blue Shield. And the member states approved the guidelines, which include recommendations to the use and implementation of the digital emblem. So getting that support and that buy -in was an enormously important step forward. But then to move it beyond those guidelines, there are still a number of steps that we need to take. The first one, Blue Shield emblems also aren't really legislated in most countries. So that's going to need to change, I think, to prevent misuse, because that's a really important step to building trust. Whereas the Red Cross is legislated in almost every country in the world. Countries are going to need to identify what they class as digital heritage. And that's something where actually civil society and even governments, government institutions are moving so much faster than government policy and legislation. And so we'll be really keen to see them actually start to recognize that this is what people want. It's what they're doing. And so it needs that same protection. We've produced a big report that will be launched very shortly at Blue Shield looking at the use and practice of Blue Shields. And it includes digital heritage and recommendations that include promoting the digital emblem to really try and raise awareness of these protective measures and how they work and how people should use them. But the big problem that we have in the heritage world is that fundamentally it's very under -resourced. It is a sector that really runs on love and interest. And digitally speaking, a lot of technology is often very old. And the technical know -how, unless you're in a major institution, is very, very low. So one of the things I was very excited to hear yesterday actually was this talk of solutions that will be standardized, that can be a bit more out of the box, that we can sort of literally help people who otherwise are not going to understand how to apply these technical protections. And to be able to say, well, actually, this is the solution. This is how you deploy it. And if they have that buy -in. from their governments to say, yes, absolutely, you deserve this protection. I think that will be actually quite a straightforward step. But it's going to need that technological investment that currently is lagging behind, unfortunately. I really look forward to seeing that start to develop.
Joelle Rizk
Thanks, Amma. If I may quickly have a follow -up with you. You alluded to it today and you spoke about it a bit more yesterday on the role of the importance of national legislation in order to advance this work. Could you say a few more words about that, thanks.
Emma Cunliffe
that place? So of the 140 states that have signed the Hague Convention and who may use the Blue Shield, there are, I think, about 40 to 50 who actually put Blue Shields on monuments. And the numbers that they place range from five to about 40,000. And that has no bearing on the size of the country either. And of those, we didn't do a thorough check of every country's legislation, but there's actually less than 10 that legislate it that we found in our spot checks. So the importance of legislating both what digital heritage is to say, yes, this is a real thing, it deserves protection, to legislate the emblem to say these are these places where it has been applied, they're real places, they're deserving of protection in conflict, IHL applies here. And then to be able to have the systems to report misuse, because our study did also find a number of cases where it did not apply. And so we've got a number of cases where it did not apply. And there are cases of misuse, and I'm sure it's unintentional. I'm sure that actually it's people who really just want the best for the places and the objects that they're protecting. But there are we need better systems in place to manage and support that. And they don't exist at the moment. But actually, the number of guidelines and recommendations coming out are huge. And to be able to implement the physical. in parallel with the digital emblem. So it's not seen as a change and a new set of things to do. Actually, the timing couldn't be better.
Joelle Rizk
Thank you, Aman. That's a good segue to my last question to Tommy. We've heard a lot about the importance of these technical standards. Are we really talking here about a tech solution? And why is the involvement of tech industry in this project, in addition to the involvement of states and national societies, why is the involvement of the industry very important? What is their role?
Tommy Jensen
So I think Emma absolutely got it correct with one word, productizing. So technically, the problem of how to signal the existence of protection with a digital emblem can be solved as an academically technical problem. And a system can be designed that works well, and we can standardize. It's something that everyone recognizes and adopts. If a medical personnel has to become an expert in computer networking in order to remove an emblem from an asset as ground is being surrendered to an incoming force, the problem has not been operationally solved. And that is the role that industry can play where vendors make this easy to deploy, that can have out -of -the -box solutions, that we make that easier for the people who need to use it that shouldn't have to be technical experts to do so.
Joelle Rizk
Thank you, Tommy. We are up on the hour. However, since we were delayed to start, I will allow us to maybe extend. If you're okay with that, by a minute or two, to maybe take a question either online or from the room. We have a question from the room. Please introduce yourself.
Audience
Hello. Hello, thank you very much for this insightful session. My name is Janine. I live in Berlin and I came here because I'm a finalist in a technical project here. I wasn't present yesterday, so I maybe don't have the other side, but I want to stress out about the capacities of different countries. First, from a legal perspective, I understand that the protection of the health industry is already protected by law and in many countries even by their own constitution. However, this hasn't actually transferred into a protection over the digital scope at all in most of the countries. And from the technical side, even in developed countries, the capacity is not the same to implement many of the things you were deploying today. And moreover, this impact not only happens in countries that are currently at war or in developed countries, but I think it's even worse since the situation becomes much more critical in developing countries. How does the project address this from a legal perspective and a technical one? Thank you so much.
Joelle Rizk
Thank you, Janine. I think all our panels have something to say about your questions. I'll start with the legal, and then we move to Tommy, Mauro, and then finally Emma. I'll give you the floor as well to add to that.
Samit D'Cunha
Thank you so much. That's a brilliant question. I'll preface this by saying, you know, that first Geneva Convention, I talked about in 1864, for all its merits, was ultimately quite a European convention. I mean, there was 12 states that signed the very first Geneva Convention. Most of them were European, and four of them became Germany. So, I mean, you know, it was a different world. The beautiful thing is that over 160 years, of course, that's been universal, right? I mentioned now the four Geneva Conventions of 196 states that are parties. And with that, indeed, comes, you know, this very important process in thinking of, well, how do we make sure that, indeed, they, you know... states all over the world medical services all over the world have the capacity to provide actually the protections that are in there in the conventions and so today with the digital emblem project that is you know clearly part of the thinking i mentioned earlier this resolution um uh i think that was adopted at the international conference resolution too that's as it's colloquially known the ict resolution i mentioned that in that resolution there's a paragraph or i didn't mention this actually paragraph 12 um of that resolution calls for you know it encourages the work that the icrc is doing on the digital emblem project but also calls on states within their capacities to provide capacity building to states that need it as well as national societies and i think when it comes to implementing ihl when it comes to implementing a lot of these protections for victims of armed conflict the national societies have been essential in building capacities in states so they work on you know national legislation they work on ensuring that the government has the technical know -how to be able to provide that kind of support to to victims of armed conflict. So I think that, you know, from the legal perspective, that is an essential component. Then there's the sort of practical application of it. And I think my co -panelists can speak on that. But when it comes to the law, that's certainly something that's being thought about that we have to make sure that, you know, we're talking about technologies here. We have to make sure that there is, you know, that there are those capacities, you know, in all of the states that want to, you know, use the digital emblem. And then just the last thing I'll say, you know, in testing the digital emblem, my colleague Mauro mentioned that indeed we're testing with some national societies. So there's eight national societies right now. The two that have been able to implement it on their infrastructure so far, of course, the British Red Cross and the Australian Red Cross. Now we need to make sure that that testing is also, you know, represents a diversity, like the diversity of the national societies that need a digital emblem. And that, you know, that's national societies in Asia, in Europe, in Africa. In South America. And so we do have national societies that are part of that initial testing group actually. all of these regions. So yeah, it's really important to make sure that they build those capacities and then they become kind of champions in their region to help others also be able to use the digital emblem in
Tommy Jensen
So from a technical perspective, this is actually a very straightforward situation of saying we have to be able to design something that works in very, very constrained environments. I attended a research group presentation at the IETF a couple of years ago where a presenter pointed out that within Palestine at one point the infrastructure that they had available was limited to 2G cellular connectivity and that was it. And when we design new technical protocols today, we don't really think of 2G as something we still need to support. We take for granted that we have better network connectivity than that and we can't do that here. Because if we do that, we are excluding parties, which is obviously a non -starter. It has to be something that's readily deployable anywhere by anyone. And while that will never be completely possible in that there's got to be some form of networking present, if you have something that is digitally available, it needs to be able to apply an emblem. So the answer to your question is we have to introduce a requirement of it has to perform in very, very poor networking conditions.
Joelle Rizk
Thank you, Tommy. Mauro, online?
Mauro Vignati
Yeah, probably not much more substantial to what already Samit and Tommy said. Just to say that, for instance, when the British and Australian Red Cross, they wanted to test it, we had them to implement and deploy the emblem. So we hope that in the future with the final solution for the emblem, there's going to be a kind of cascading effect where the we can help some of the major actors that will also help others. actors so we we hope to have this cascading effect in the future so that the the knowledge and the capability on how to deploy this easy solution will be will be shared among among all the the actors.
Joelle Rizk
Thank you marion emma finally to you.
Emma Cunliffe
So it's a really important question and i think it's not one we talk about often enough actually so for example in part of my role i'm also the coordinator for our national committee network and we don't have as many we have we've got uh 35 nearly 40 there's there's more under construction but in our our worst affected countries you know the president of the committee has to drive two hours to download a file if i email it to him because the technology is not there to support him and so we are we're really mindful of that so some of the ways we're going to be looking at taking this forwards um we run training every year for our national committees and we try to fund them to come because obviously that's another gap um And these are the cuts. So then, as Samit said, then they would be able to act as champions to advocate with their governments because the Blue Shirt legislation has to unfortunately be quite sort of top down as much as you can advocate from it from the bottom. UNESCO are going to be key advocates like the work they were doing last year to advocate for this with the member state parties is really important. And then the other area that I think we'll really be focusing on for us is that a lot of the big funding bodies that fund heritage preservation in crisis areas do a lot of digitization work, actually huge amounts. They're really embedded in digital heritage and protection of digital heritage. And they are going to be really key advocates for this work as it becomes possible to take it forwards. So, you know, in my imagination, I haven't talked to any of them about this, but I would love to see them. And so, well, actually, if you're doing this digital heritage project, actually, have you considered this? You know, here are contacts for your government to be able to. to talk about protecting this work going forwards, perhaps, because then they'll also be, as part of that digitization work, they're usually supplied with improved digital infrastructure, which is then also hand -in -hand given capacity to implement it. So it's really going to be a multi -partner approach of civil society and NGOs, governments, huge international agencies like UNESCO, funders. And that's the only way we can make this work. But I think there's so much interest and desire that I'm really hopeful.
Joelle Rizk
Thank you, Emma, and thank you for all the panelists. Unfortunately, we have run out of time on the session, but I'll just close by saying the importance of the digital emblem is a reflection of the importance of the services of which it's signaling protection under international law. An attack against a medical service in the cyberspace, in the digital space. time of armed conflict could mean life and death to civilians. An attack against a database of a humanitarian organization could hinder the delivery of its protection services, including, for example, finding people that have gone missing. So the consequences are quite severe and important, which is why this project is very important and has a very complex task ahead of it to achieve that signaling of that protection in a way that combines legal norms and technical standards. So it's a very ambitious project, yet a very complex one. But as was said yesterday, its purpose is actually very simple, and that is to make international humanitarian law protections visible, detectable, and verifiable in cyber operations during armed conflict. On that note, I thank you all. I wish you a good lunch, and I wish the team here working on the Shlombdyn project all the best in the future

Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.