Confidentiality Metadata-Based Access Control & Federated Mission Networking
About the author
Steve Kille has worked for many years on open standards for Messaging, XMPP, Directory, Security, and HF Radio. He has worked on CCITT, IETF, XSF, and NATO standards (currently editing STANAG 5066), which have been implemented by Isode.
He is also Isode’s CEO

Confidentiality Metadata-Based Access Control (CMBAC) and Federated Mission Networking (FMN)
Federated Mission Networking (FMN) is a NATO model for nations participating in a joint exercise. A Federated Mission Network involves multiple national networks becoming interconnected so their combined forces can operate as a single cohesive unit. This requires many security protocols to be established and adhered to, and often involves shared network infrastructure, such as IP routers and domain name services, while maintaining a national system for each partner force. This creates a unique problem and requires software and applications capable of handling such setups.
Isode’s messaging and XMPP products use open federated protocols, so they work naturally in an FMN setup. NATO Data Centric Security (DCS) work raises some interesting implications, which are explored in a recent Isode white paper titled “Data Centric Security and Federated Mission Networking.”
Security Labels are central to DCS, and NATO is moving to standardized confidentiality labels as defined in STANAG 4774. One aspect of this is having clients add security labels. In a cross-domain environment, labels are checked at the cross-domain boundary, as might have been done in older Network-Centric Security.
An FMN system lacks cross-domain boundaries, yet there is still a need to enforce access to messages. The NATO approach to this is called Confidentiality Metadata-Based Access Control (CMBAC), which means checking confidentiality labels against STANAG 4774 confidentiality clearances.
CMBAC controls are central to providing DCS using confidentiality labels. In XMPP and messaging applications, the key control function is to ensure that messages are delivered only to users with clearance to access them, based on the message’s security label. More details explaining exactly how this works can be found in the white paper linked above.