Agent Sessions and Tool Authentication

By Google Cloud Tech

Share:

Key Concepts

  • Agent Development Kit (ADK): A framework for building agents that interact with enterprise data.
  • Authenticated Tools: Specific, defined functions that an agent can use to access data, with built-in authentication mechanisms.
  • ADK Session: Represents a single, continuous conversation with a user, managing user-specific state, including authentication tokens.
  • Authentication Token: A credential used to verify a user's identity and authorize access to data.
  • Retrieval Service: A backend component that acts as a gatekeeper for the database, verifying tokens and fetching user-specific data.
  • Sensitive Data Protection (SDP): A service that scans and redacts or masks sensitive data.
  • Model Armor: A component that inspects data and responses for data loss prevention.

Secure Agent Interaction with User-Specific Database Data

This discussion outlines a secure pattern for building agents, particularly those developed with frameworks like the Agent Development Kit (ADK), to interact with sensitive user-specific data stored in a database. The core challenge is to grant agents the power to access and manipulate enterprise data while rigorously safeguarding user privacy.

The Authenticated Tool Pattern

The primary strategy for achieving secure data interaction is to limit the agent's access by preventing direct database access for the underlying model. Instead, the approach utilizes authenticated tools. These are predefined, specific functions that the agent can invoke. Crucially, the authentication for these tools is tied to the user's session.

ADK Session Management and Workflow

The ADK framework facilitates this pattern through its session management capabilities.

  1. User Login and Token Acquisition: The application first handles user login, obtaining an authentication token for the user.
  2. ADK Session Creation: When a user initiates a conversation, the application creates an ADK session. This session is associated with a unique session ID and stores the user's authentication token.
  3. User Request and Tool Invocation: The user makes a request, such as "list my flight tickets." The agent analyzes this request and determines that it needs to use a specific tool, in this case, a list_tickets tool.
  4. Tool Execution with Session Context: The ADK framework then invokes the code for the list_tickets tool. It passes the context of the current session to the tool.
  5. Token Retrieval and Backend Call: The tool's code uses the session ID to retrieve the correct user authentication token from the backend. This token is then attached to the request headers when calling a backend retrieval service.
  6. Retrieval Service as Gatekeeper: The retrieval service acts as a critical intermediary. It verifies the authentication token and retrieves the corresponding user ID.
  7. User-Specific Database Query: Using the verified user ID, the retrieval service queries the database. This ensures that only information pertaining to that specific user is fetched.
  8. Data Return to Agent: The retrieved, user-specific data is returned to the agent.
  9. Agent Response Formulation: The agent then processes this data to formulate a response for the user.

Security Benefits of the Pattern

This design offers significant security advantages:

  • No Direct Model Access: The agent and the underlying LLM never directly see the authentication token or have direct access to the database.
  • Scoped Data Access: The agent only has access to the data returned for the single authenticated user within that specific session.
  • Sandboxed Agent Instances: Each user effectively gets a dedicated agent instance that is sandboxed and only has access to their own information.
  • Server-Side Session Management: The session ID is managed server-side and is not exposed to the user's client. This prevents attackers from attempting to steal or spoof session IDs.
  • LLM Ignorance of Authentication: The LLM itself has no awareness of the session ID or the user's token. Authentication is handled by predictable application code, not the LLM.

Additional Safeguards: SDP and Model Armor

To further enhance security, two additional services can be integrated:

  • Sensitive Data Protection (SDP):
    • Data Redaction/Masking: SDP can scan data retrieved from the database before it reaches the model. It can redact or mask sensitive information, further protecting privacy.
    • Response Inspection: SDP can also inspect the agent's final response to the user, acting as an additional layer of data loss prevention.
  • Model Armor: This component works in conjunction with SDP to provide these scanning and inspection capabilities.

Conclusion

By combining ADK session management with the authenticated tool pattern and integrating services like SDP and Model Armor, it is possible to build powerful agents that can securely access and interact with sensitive user-specific data without compromising security. This approach ensures that authentication is robust, data access is strictly controlled, and user privacy is maintained.

Chat with this Video

AI-Powered

Load the transcript when you're ready to chat so the initial page stays lighter.

Ready to summarize another video?

Summarize YouTube Video