IP Library › Granted Patent US 12,505,131
Granted Patent B2
US 12,505,131 · App. 19/249,448 · Granted Dec 23, 2025

Sidecar security pattern for agent communications

Inventors: Vijay Madisetti (Alpharetta, GA); Arshdeep Bahga (Chandigarh, IN)
Assignee: Vijay Madisetti
G06F16/3329G06F40/284
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,131
App. No.
19/249,448
Filed
Jun 25, 2025
Granted
Dec 23, 2025
Kind
B2
Art Unit
3629
USPC
705/304
Abstract

Systems and methods for securing agent communications in a multi-agent system including deploying an agent to communicate with external servers, instantiating a sidecar security service in communication with the agent and including at least one of a guardrails service, a security layer, an encryption module, and an integrity checker configured to validate resources tools using hash-based verification mechanisms. Communications including messages between the primary and the external servers are intercepted by the sidecar security service, which then performs at least one of filtering the one or more messages by the guardrails service, authenticating one or more server connections by the security layer, encrypting one or more outbound requests by the encryption module, or verifying an integrity of resources and tool definitions by the integrity checker.

Claims (65)

1 . A method for securing agent communications in a multi-agent system comprising:

deploying a primary agent configured to communicate with one or more external servers via a standardized protocol;

instantiating a sidecar security service in communication with the primary agent, the sidecar security service comprising:

a guardrails service configured to enforce safety constraints on message content and validate protocol compliance;

a security layer configured to implement authentication and authorization mechanisms for server connections;

an encryption module configured to encrypt transport layer communications between the primary agent and external servers; and

an integrity checker configured to validate resources and tools using hash-based verification mechanisms;

intercepting communications comprising one or more messages between the primary agent and the one or more external servers by the sidecar security service;

filtering the one or more messages by the guardrails service;

authenticating one or more server connections between the primary agent and the one or more external servers by the security layer before establishing communication channels;

encrypting one or more outbound requests transmitted by the primary agent comprised by the one or more messages and decrypting inbound responses from the one or more external servers comprised by the one or more messages by the encryption module; and

verifying an integrity of resources and tool definitions comprised by the primary agent by the integrity checker.

2 . The method of claim 1 wherein:

the primary agent operates in a first container;

the sidecar security service operates in a second container separate from the first container; and

the first and second containers are comprised by a pod.

3 . The method of claim 1 wherein the guardrails service is further configured to filter personally identifiable information (PII) from the one or more messages before transmission to external servers.

4 . The method of claim 1 wherein the integrity checker employs each of a parity bit mechanism and a hash-based verification mechanism for message validation.

5 . The method of claim 1 wherein the sidecar security service further comprises a logging service configured for audit trail maintenance, the method further comprising logging all interactions by the logging service.

6 . The method of claim 1 wherein:

the sidecar security service comprises two or more of:

a guardrails service configured to enforce safety constraints on message content and validate protocol compliance;

a security layer implementing authentication and authorization mechanisms for server connections;

an encryption module configured to encrypt transport layer communications between the primary agent and external servers;

an integrity checker configured to validate resources and tools using hash-based verification mechanisms; and

the method further comprises performing two or more of:

filtering the one or more messages by the guardrails service;

authenticating the one or more server connections between the primary agent and the one or more external servers by the security layer before establishing communication channels;

encrypting the one or more outbound requests transmitted by the primary agent comprised by the one or more messages and decrypting the inbound responses from the one or more external servers comprised by the one or more messages by the encryption module; and

verifying the integrity of resources and tool definitions comprised by the primary agent by the integrity checker.

7 . A system for securing agent communications in a multi-agent system comprising:

a processor;

a network communication device operably coupled to the processor and configured to transmit and receive digital messages across a computer network; and

a non-transitory computer-readable medium having stored thereon software, executed by the processor, operable to:

deploy a primary agent configured to communicate with one or more external servers via a standardized protocol;

instantiate a sidecar security service in communication with the primary agent, the sidecar security service comprising:

a guardrails service configured to enforce safety constraints on message content and validate protocol compliance;

a security layer implementing authentication and authorization mechanisms for server connections;

an encryption module configured to encrypt transport layer communications between the primary agent and external servers; and

an integrity checker configured to validate resources and tools using hash-based verification mechanisms;

intercept communications comprising one or more messages between the primary agent and the one or more external servers by the sidecar security service;

filter the one or more messages by the guardrails service;

authenticate one or more server connections between the primary agent and the one or more external servers by the security layer before establishing communication channels;

encrypt one or more outbound requests transmitted by the primary agent comprised by the one or more messages and decrypting inbound responses from the one or more external servers comprised by the one or more messages by the encryption module; and

verify an integrity of resources and tool definitions comprised by the primary agent by the integrity checker.

8 . The system of claim 7 wherein:

the primary agent operates in a first container;

the sidecar security service operates in a second container separate from the first container; and

the first and second containers are comprised by a pod.

9 . The system of claim 7 wherein the guardrails service is further configured to filter personally identifiable information (PII) from the one or more messages before transmission to external servers.

10 . The system of claim 7 wherein the integrity checker employs each of a parity bit mechanism and a hash-based verification mechanism for message validation.

11 . The system of claim 7 wherein:

the sidecar security service further comprises a logging service configured for audit trail maintenance; and

the software, when executed by the processor, is further operable to log all interactions by the logging service.

12 . The system of claim 7 wherein:

the sidecar security service comprises two or more of:

a guardrails service configured to enforce safety constraints on message content and validate protocol compliance;

a security layer configured to implement authentication and authorization mechanisms for server connections;

an encryption module configured to encrypt transport layer communications between the primary agent and external servers;

an integrity checker configured to validate resources and tools using hash-based verification mechanisms; and

the software, when executed by the processor, is further operable to perform two or more of:

filter the one or more messages by the guardrails service;

authenticate between the primary agent and the one or more external servers by the security layer before establishing communication channels;

encrypt the one or more outbound requests transmitted by the primary agent comprised by the one or more messages and decrypting the inbound responses from the one or more external servers comprised by the one or more messages by the encryption module; and

verify the integrity of resources and tool definitions comprised by the primary agent by the integrity checker.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2025
From: BAHGA, ARSHDEEP
To: MADISETTI, VIJAY
Reel/Frame 071544/0296 →
Continuity (14)
Continuation 18921852 · Oct 21, 2024
Continuation In Part 18812707 · Aug 22, 2024
Continuation In Part 18470487 · Sep 20, 2023
Continuation 18348692 · Jul 7, 2023
Provisional Application 63693351 · Sep 11, 2024
Provisional Application 63647092 · May 14, 2024
Provisional Application 63607647 · Dec 8, 2023
Provisional Application 63607112 · Dec 7, 2023
Provisional Application 63535118 · Aug 29, 2023
Provisional Application 63534974 · Aug 28, 2023
Provisional Application 63529177 · Jul 27, 2023
Provisional Application 63469571 · May 30, 2023
Provisional Application 63463913 · May 4, 2023
Related Publication 20250321992A1 · Oct 16, 2025
References Cited (6)
US 20080015808A1 · Wilson · 2008 [cited by examiner]
US 20160226710A1 · Cha · 2016 [cited by examiner]
US 20180314703A1 · Bull · 2018 [cited by examiner]
US 20210240818A1 · Seksenov · 2021 [cited by examiner]
US 20210303558A1 · Setlur · 2021 [cited by examiner]
G. A. S. Torrellas and L. B. Sheremetov, “An authentication protocol for agent platform security manager,” EFTA 2003. 2003 IEEE Conference on Emerging Technologies and Factory Automation. Proceedings (Cat. No. 03TH8696)… [cited by examiner]
Cited By (1)
US 12,572,471