Home

⚠️ Work in Progress: This project and documentation are currently under active development.

nmbs is a lightweight, minimal implementation of NATO security labeling and metadata binding standards. It provides parsing, validation, and encoding utilities to enable a free alternative to applying confidentiality metadata to files, without the need for heavy and expensive Data Loss Protection (DLP) suites.

nmbs has two primary use cases:

  1. On desktop machines within controlled networks to enable end users to label files. In combination with enterprise DLP at the network edge, the network can scale without the need for per-machine licenses, just to label files.

  2. Embeded in other applications, allowing software developers to tag files when they are written, or read labels when opening files and correctly display marking data.

 


Key Features

  • Embedded Labels: Such as NATO UNCLASSIFIED, or ORGANISATION INTERNAL.
  • Its Fast: High-performance C/C++ metadata parsing and construction.
  • Standard Compliant: Strict adherence to NATO specifications.
  • Packaging Friendly: Built for easy integration into Linux environments and Debian packaging workflows.
  • GNOME Integration: Seamlessly integrated into GNOME Files.
  • Headless Support: Operation on servers via a CLI.
  • Multi Language: English, French and German internationalisation.

 


GNOME Files Integration

nmbs Nautilus Integration Example


CLI

nmbs-get
nmbs-set
nmbs-verify

 


Supported NATO Standards

nmbs implements specifications published by NATO:

  • ADatP 4774 Ed.A V.1 — CONFIDENTIALITY METADATA LABEL SYNTAX Defines the structure and XML schema used to express confidentiality labels attached to data objects.
  • ADatP 4778 Ed.A V.1 — METADATA BINDING MECHANISM Defines the methods for securely encapsulating and binding metadata (such as ADatP 4774 labels) to data payloads.

 


Protocol Implementation Conformance Statement (PICS)

Standard Feature / Module Support Level
ADatP 4774 Security Policy Information File Read
  Confidentiality Label Read/Write
  Confidentiality Celarance -
  Access Control Framework -
  Label Catalogs -
ADatP 4778 urn:nato:stanag:4778:profile:cryptoartefact:1:2 -
  urn:nato:stanag:4778:profile:smtp:1:2 -
  urn:nato:stanag:4778:profile:xmpp:1:3 -
  urn:nato:stanag:4778:profile:ooxml:1:2 -
  urn:nato:stanag:4778:profile:soap:1:1 -
  urn:nato:stanag:4778:profile:rest:1:2 Read/Write
  urn:nato:stanag:4778:profile:gopc:1:2 -
  urn:nato:stanag:4778:profile:sidecar:1:2 Read/Write
  urn:nato:stanag:4778:profile:xmp:1:1 Read/Write
  urn:nato:stanag:4778:profile:wsmp:1:1 -
  urn:nato:stanag:4778:profile:xml:schema:1:0 Read

 


Quick Code Example

#include <nmbs/nmbs.h>

int main()
{
    const std::filesystem::path file{"my-image.jpg"};

    std::vector<nmbs::ConfidentialityLabel> labels(1);
    labels[0].confidentiality_information.policy_identifier = "PUBLIC";
    labels[0].confidentiality_information.classification = "UNMARKED";

    nmbs::write_labels(file, labels);
    
    return 0;
}