Secure data channel in online game system

By using public key encryption technology to generate and manage channel keys in cloud gaming systems, a secure data channel is established, and the security problems of users' generated data sharing in online gaming systems are solved, and user privacy and content security protection is achieved.

CN119951146APending Publication Date: 2025-05-09SONY INTERACTIVE ENTERTAINMENT LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510190160.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2018-12-20
Filing Date
2019-12-11
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

In existing online game systems, user-generated data lacks security when shared, and is easily intercepted by malicious parties or hacked, resulting in user privacy and content exposure.

Method used

By establishing a secure data channel in the cloud gaming system, generating channel keys using public key encryption technology, and encrypting the transmitted content by encrypting the channel keys, ensuring that only users of the data channel can decrypt and access the message content.

Benefits of technology

It realizes the secure sharing of user content and information in online game systems, protects user privacy, and prevents unauthorized access and data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119951146A_ABST
    Figure CN119951146A_ABST
Patent Text Reader

Abstract

In one embodiment, a method includes initiating a data channel through a network gaming service, including generating a channel key for encrypting content communicated through the data channel, and generating a first encrypted channel key by encrypting the channel key using a public key associated with an owner of the data channel; adding a participant to the data channel, including generating a second encrypted channel key by encrypting the channel key using a public key associated with the participant; wherein a message sent through the data channel includes encrypted content generated by encrypting content of the message using the channel key, and further includes the first encrypted channel key and the second encrypted channel key.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This patent application is a divisional application of the following invention patent applications:

[0002] Application number: 201980089949.4

[0003] Application date: December 11, 2019

[0004] Invention Title: Secure Data Channel in Online Gaming System Technical Field

[0005] The present disclosure relates to systems and methods for secure data channels in an online gaming system that enable secure sharing of information, thereby protecting user privacy of user-generated data. Background Art

[0006] Description of Related Technology

[0007] A rapidly developing area of ​​technology is the field of video games, which now encompasses numerous gaming platforms, including dedicated game consoles, personal computers (PCs), and more recently, cloud gaming and mobile devices. Game play has become increasingly social, as players desire social interactions centered around the game. As a result, networked gaming services / systems have been developed that include communication mechanisms between players, enabling communication and social interaction both during game play and outside of game play but still within the context of the video game platform. An example of a networked gaming service / system is Network, which includes a variety of gaming services that support both console-based and cloud-based gaming.

[0008] In a cloud gaming setup, a user is able to access a number of games on a cloud gaming site over a network (such as the Internet) and begin interacting / playing. To select a game to play, the user accesses his / her account on the cloud gaming site and launches one of the multiple games available for play by the user account. The video generated from the cloud video game is transmitted to the client device. An example of a cloud gaming system is Now cloud gaming service.

[0009] It is against this background that embodiments of the present disclosure are presented. Summary of the invention

[0010] Implementations of the present disclosure provide methods and systems for providing a secure data channel for sharing information in a cloud gaming system.

[0011] In some implementations, a method is provided, the method comprising the following operations: initiating a data channel through a network game service, including generating a channel key, the channel key being used to encrypt content transmitted through the data channel, and generating a first encrypted channel key by encrypting the channel key using a public key associated with an owner of the data channel; adding a participant to the data channel, including generating a second encrypted channel key by encrypting the channel key using a public key associated with the participant; wherein a message sent through the data channel includes encrypted content generated by encrypting content of the message using the channel key, and also includes the first encrypted channel key and the second encrypted channel key.

[0012] In some implementations, after the user device associated with the owner receives the message, the channel key is decrypted from the first encrypted channel key using a private key associated with the owner, and the decrypted channel key is further used to decrypt the encrypted content of the message.

[0013] In some implementations, after a user device associated with the participant receives the message, the channel key is decrypted from the second encrypted channel key using a private key associated with the participant, and the decrypted channel key is further used to decrypt the encrypted content of the message.

[0014] In some implementations, the method further includes removing the participant from the data channel, including generating a second channel key, and generating a third encrypted channel key by encrypting the second channel key using the public key associated with the owner.

[0015] In some implementations, the second channel key is not encrypted with the public key associated with the participant.

[0016] In some implementations, the method further includes adding a second participant to the data channel, including generating a third encrypted channel key by encrypting the channel key using a public key associated with the second participant.

[0017] In some implementations, the message sent through the data channel also includes the third encryption channel key.

[0018] In some implementations, a method is provided, the method comprising the following operations: receiving a first encrypted channel key of a data channel from an owner device associated with an owner of the data channel via a network, the first encrypted channel key being a channel key encrypted with a public key associated with the owner of the data channel, the channel key being used to encrypt content shared via the data channel; receiving one or more secondary encrypted channel keys from the owner device via the network, each secondary encrypted channel key being a channel key encrypted with a public key associated with a corresponding participant of the data channel; storing the first encrypted channel key and the one or more secondary encrypted channel keys into a channel list; distributing the channel list to one or more participant devices respectively associated with each participant of the data channel via the network; wherein communications on the data channel include the first encrypted channel key, the secondary encrypted channel key, and content encrypted using the channel key.

[0019] In some implementations, after the owner device receives a communication through the data channel, the channel key is decrypted from the first encrypted channel key using a private key associated with the owner, and the decrypted channel key is further used to decrypt the encrypted content of the communication.

[0020] In some implementations, after a participant device receives a communication through the data channel, the channel key is decrypted from the secondary encrypted channel key using a private key associated with the participant, and the decrypted channel key is further used to decrypt the encrypted content of the communication.

[0021] In some implementations, the method further includes: receiving a first encrypted second channel key of the data channel from the owner device via a network to exclude at least one of the participants, the first encrypted second channel key being a second channel key encrypted with the public key associated with the owner of the data channel, the second channel key being used to encrypt content shared via the data channel; receiving one or more secondary encrypted second channel keys from the owner device via the network, each secondary encrypted second channel key being the second channel key encrypted with the public key of one of the participants, wherein the one or more secondary encrypted second channel keys do not include a secondary encrypted second channel key that is the second channel key encrypted with the public key of at least one of the participants excluded; updating the channel list to include the first encrypted second channel key and the one or more secondary encrypted second channel keys; and distributing the updated channel list to the participant devices via the network.

[0022] In some implementations, the additional communication on the data channel includes the first encrypted second channel key, the second encrypted second channel key, and content encrypted using the second channel key.

[0023] In some implementations, the method further includes: storing the communication on the data channel; storing the additional communication on the data channel.

[0024] In some implementations, the channel key allows the at least one excluded one of the participants to access content of the stored communications, and wherein the second channel key prevents the at least one excluded one of the participants from accessing content of additional stored communications.

[0025] In some implementations, a non-transitory computer-readable medium is provided, on which program instructions are embodied, which, when executed by at least one processor, cause the at least one processor to perform a method comprising the following operations: initiating a data channel through an online gaming service, comprising generating a channel key, wherein the channel key is used to encrypt content transmitted through the data channel, and generating a first encrypted channel key by encrypting the channel key using a public key associated with an owner of the data channel; adding a participant to the data channel, comprising generating a second encrypted channel key by encrypting the channel key using a public key associated with the participant; wherein a message sent through the data channel comprises encrypted content generated by encrypting content of the message using the channel key, and also comprises the first encrypted channel key and the second encrypted channel key.

[0026] Other aspects and advantages of the present disclosure will become apparent from the following detailed description, taken in conjunction with the accompanying drawings, illustrating by way of example the principles of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] The present disclosure and further advantages thereof may be best understood by referring to the following description taken in conjunction with the accompanying drawings.

[0028] Figure 1A Conceptually illustrates the exchange of public keys between a data channel and multiple users in accordance with implementations of the present disclosure.

[0029] Figure 1B Further illustrated is the processing of communications between the data channel 100 and users of the data channel 100 according to implementations of the present disclosure.

[0030] Figure 2 Several users' interactions with the data channel 100 are shown in accordance with implementations of the present disclosure.

[0031] Figure 3 A system for providing a data channel to achieve information sharing according to an implementation of the present disclosure is conceptually illustrated.

[0032] Figure 4 The transfer of ownership of the data channel 100 according to an implementation of the present disclosure is conceptually illustrated.

[0033] Figure 5 The revocation of access to the data channel 100 according to an implementation of the present disclosure is conceptually illustrated.

[0034] Figure 6 Conceptually illustrated is game-related communications / data transmitted via an encrypted data channel in accordance with an implementation of the present disclosure.

[0035] Figure 7 An interface for accessing content from a data channel according to an implementation of the present disclosure is conceptually illustrated.

[0036] Fig. 8A A process for initiating a cryptographically private player social data channel in accordance with an implementation of the present disclosure is conceptually illustrated.

[0037] Figure 8B A process for adding participants to a data channel according to an implementation of the present disclosure is conceptually illustrated.

[0038] Figure 8C The change of the channel list of encryption channel keys for a data channel when a user leaves the data channel according to an implementation of the present disclosure is conceptually illustrated.

[0039] Fig.8D A timeline is conceptually shown according to an implementation of the present disclosure, the timeline showing the content of a data channel based on Figure 8C Encryption of scenes over time.

[0040] Fig. 8E Components of a message in a data channel 100 according to an implementation of the present disclosure are conceptually illustrated.

[0041] Fig.9A A simplified block diagram of an exemplary system for preloading game content onto a cloud gaming server is shown according to an embodiment of the present disclosure.

[0042] Fig. 9B is a flow diagram conceptually illustrating various operations performed for streaming a cloud video game to a client device in accordance with an implementation of the present disclosure.

[0043] Fig.10An exemplary information service provider architecture for delivering information content and services to users who are geographically dispersed and connected via a network is shown in accordance with implementations of the present disclosure. DETAILED DESCRIPTION

[0044] In the following description, many specific details are set forth in order to provide a thorough understanding of the present disclosure. However, it will be apparent to those skilled in the art that the present disclosure may be practiced without some or all of these specific details. In other cases, well-known process steps are not described in detail in order to avoid making the present disclosure unclear.

[0045] As the popularity of the video gaming sector continues to grow, the amount of user-generated information associated with video games has also grown. The gaming experience has evolved to facilitate greater social interaction, such as through text / audio / video chat, audio feeds, video feeds, screenshots, video clips, social posts, comments, etc. Additionally, as cloud gaming expands, more and more user information is stored in the cloud rather than locally. Therefore, it is desirable to ensure the security and privacy of user data while also enabling users to control access to data based on their preferences.

[0046] As mentioned above, such as Networks can provide a variety of gaming services that support both console-based and cloud-based gaming. However, while such network gaming services can provide communication and social services to users, user content and information shared through such services may not be secure and visible to the network gaming service provider. For example, such content may be intercepted by malicious parties. In addition, if the network gaming service is hacked, the user's information and content may be exposed.

[0047] In view of the above, the implementation of the present disclosure provides a secure data channel for communication between users of a network game service. The data channel can be instantiated and controlled by one of the users as the data channel owner / administrator, including controlling the addition of users and the removal of users from the data channel. Content shared through the data channel can be encrypted so that only the users of the data channel can read it.

[0048] For ease of description, throughout this disclosure, it should be understood that references to "user" are generally synonymous with a user device associated with or operated by a user, as a user typically interfaces with a system according to this disclosure by using or operating a user device. Therefore, while the term "user" is used in this disclosure for ease of description, it should be understood that the term "user" may include both a user and a user device operated by or otherwise associated with a user, and further, the terms "user" and "user device" are often used interchangeably in the current description of implementations, which will be apparent to those skilled in the art.

[0049] Figure 1A The exchange of public keys between a data channel and multiple users according to an implementation of the present disclosure is conceptually illustrated. A data channel 100 is illustrated, which is to be understood as a persistent session in which multiple users participate. The data channel 100 is configured to store user-generated content or information and make such content / information accessible to participating users. In some implementations, the data channel 100 can be conceptualized as a user-generated or user-contributed content stream that records or serves as a repository for content contributions shared to the data channel 100. Such content contributions can then be accessed by anyone who has access to the stream defined by the data channel 100.

[0050] To promote data security, in the illustrated implementation, a public key exchange is performed for each user who has access to the data channel 100. That is, in the illustrated implementation, the public key of the data channel 100 is provided to and stored by user A, and the public key of user A is provided to and stored by the data channel 100. Communications from the data channel 100 to user A may be encrypted using the public key of user A, and communications from user A to the data channel 100 may be encrypted using the public key of the data channel 100.

[0051] Similarly, in the illustrated implementation, the public key of data channel 100 is provided to and stored by user B, and the public key of user B is provided to and stored by data channel 100. Communications from data channel 100 to user B may be encrypted using user B's public key, and communications from user B to data channel 100 may be encrypted using the public key of data channel 100.

[0052] Similarly, in the illustrated implementation, the public key of data channel 100 is provided to and stored by user C, and the public key of user C is provided to and stored by data channel 100. Communications from data channel 100 to user C may be encrypted using the public key of user C, and communications from user C to data channel 100 may be encrypted using the public key of data channel 100.

[0053] Figure 1B Further illustrated is the processing of communications between a data channel 100 and a user of the data channel 100 in accordance with an implementation of the present disclosure. In the illustrated implementation, a communication 102 from the data channel 100 to user A may be encrypted using user A's public key 104. Upon receiving the communication 102, user A decrypts the communication 102 using user A's private key 106, presenting the content of the communication 102. When user A sends a communication 108 to the data channel 100, the communication 108 may be encrypted using the data channel 100 public key 110. Upon receiving the communication 108, the communication 108 is decrypted using the data channel 100 private key 112, presenting the content of the communication 108.

[0054] Similar processing also occurs for communications between data channel 100 and users B and C. In the illustrated implementation, communications from data channel 100 to user B may be encrypted using user B's public key 114; and upon receipt, user B decrypts the communications using user B's private key 116, thereby presenting the contents of the communications. When user B sends communications to data channel 100, the communications may be encrypted using the public key 110 of data channel 100; and upon receipt, the communications may be decrypted using the private key 112 of data channel 100, thereby presenting the contents of the communications. Additionally, in the illustrated implementation, communications from data channel 100 to user C may be encrypted using user C's public key 118; and upon receipt, user C may decrypt the communications using user C's private key 120, thereby presenting the contents of the communications. When user C sends communications to data channel 100, the communications may be encrypted using the public key 110 of data channel 100; and upon receipt, the communications may be decrypted using the private key 112 of data channel 100, thereby presenting the contents of the communications.

[0055] Figure 2 Several user interactions with the data channel 100 are shown in accordance with implementations of the present disclosure. As described, the data channel 100 defines a persistent session in which user-generated content is stored and made accessible to users who have access to the data channel 100.

[0056] In some implementations, data channel 100 can be initiated by a specific user of the network game service, such as user A in the implementation shown. Therefore, user A is the owner of data channel 100 and has management rights to manage data channel 100. User A can invite other users of the network game service to join data channel 100, such as users B, C and D in the implementation shown. As the administrator of data channel 100, user A controls who can access data channel 100, and can also determine what permissions other users are granted, such as whether they can read / view / access the content of data channel 100, access only certain types of content, publish / write / add content to data channel 100, publish only certain types of content, invite others to read and / or publish to data channel 100, delete content from data channel 100, edit content in data channel 100, etc. As described above, data related to users of data channel 100 can be stored as user metadata 200, as shown in the figure, and the user metadata can include the user's ID, their respective public key and specific permissions.

[0057] It should be understood that when a new user joins the data channel 100, the public key exchange between the data channel 100 and the new user can be performed as described above, so that the communication between the data channel 100 and the new user can be encrypted accordingly. The public key of the new user is stored as part of the user metadata 200 along with their ID and permission information.

[0058] The data channel 100 is defined so that multiple users can share content with each other in a secure manner. Such user-generated content is stored to a content storage device 204. In addition, information related to the user-generated content is stored as content metadata 202. Non-limiting examples of content metadata include the ID of the creator of the content item, the timestamp when the content item was published, the unique identifier of the content item, the content type (e.g., text, image, video, etc.), keywords / tags, descriptors, classifications, etc.

[0059] In the illustrated implementation, user A contributes / publishes text item 206 to data channel 100, and subsequently publishes image 208 to data channel 100. User B publishes text item 212 to data channel 100, and subsequently publishes video 210. User D publishes text item 214 to data channel 100. It should be understood that according to implementations of the present disclosure, communications from users for publishing their respective content items may be encrypted with the public key of data channel 100. User C does not have write access to data channel 100, and therefore there is no publication of user C to data channel 100.

[0060] In the illustrated implementation, all users have read permissions for the data channel 100, so they are all able to view and access the various contents that have been published to the data channel 100. In some implementations, the interface through which the contents of the data channel 100 are accessed can be in the form of a feed or content stream. In some implementations, the content is accessed through an interface having different parts of the content organized by content type. In some implementations, the content is provided in the form of a chat log. Regardless of the specific interface format for presenting the content, it should be understood that the content can be securely transmitted from the data channel 100 to the user by encrypting the content with the corresponding public keys of the respective users.

[0061] It should be understood that any of a variety of types of content may be shared via the data channel 100. For example, text, images, audio, video, and combinations thereof may all be shared. In the context of cloud gaming, such content may originate from a variety of sources or interactions related to cloud gaming. Examples include, by way of example and not limitation, chat logs, game event logs, recorded audio of user audio chats, screenshots, video clips of game play, recorded video of a user's local environment, network links, and the like.

[0062] In some implementations, content shared via the data channel 100 may include live streaming of game play video from a live video game session to the data channel 100. That is, a live video feed of a user's game session may be provided to other users of the data channel 100 for viewing. In some implementations, the live video may also include live video from a user's local camera (e.g., a personal webcam) that may display the user's video. It should be understood that such live video sharing may be sensitive, and therefore the user may wish to ensure the privacy of such sharing, and the data channel 100 provides a mechanism to enable such sharing while protecting user privacy and the security of user information.

[0063] In some implementations, a user may configure the data channel 100 to automatically record certain types of events. It should be understood that a user may authorize such automatic sharing of the data channel 100 through an interface that allows selection of the type of content to be specifically shared to the data channel 100. In this manner, the data channel 100 may be automatically populated with the selected type of content. In various implementations, any type of content described herein as being shareable via the data channel 100 may be configured to be automatically shared to the data channel 100.

[0064] In some implementations, data channel 100 can be instantiated for a specific game session or event occurring on the cloud gaming system. For example, data channel 100 can be defined for a multi-player session of a video game, where content from the multi-player session is shared to data channel 100. In some implementations, players of the multi-player session (e.g., players forming a team of the video game session) are provided access to data channel 100 so that they can have a secure channel for sharing and communication.

[0065] It should be understood that the data channel 100 may also be closed or terminated by a user with administrative privileges. For example, user A in the illustrated implementation may have the ability to close the data channel 100 so that no further information is shared with the data channel 100. In some implementations, the user may still be allowed to view the data channel 100, but will not be able to add any new information to the data channel 100. This can be considered equivalent to user A removing write privileges for all users while retaining read privileges for users.

[0066] Figure 3 A system for providing a data channel to enable information sharing according to an implementation of the present disclosure is conceptually illustrated. In the illustrated implementation, user A, user B, and user C operate user / client devices 300, 302, and 304, respectively. User devices 300, 302, and 304 communicate with a channel server 308 via a network 306. The channel server 308 instantiates data channel sessions, such as data channel sessions 310, 312, and 314 in the illustrated implementation. It should be understood that each data channel session provides functionality for a different data channel according to an implementation of the present disclosure, including receiving content, storing content, and sharing content over a network to users who have access to the content of the data channel.

[0067] In the illustrated implementation, the data channel session accesses a channel metadata storage 316 and a channel media storage 326. The channel metadata storage 316 contains metadata for each data channel. By way of example and not limitation, channel metadata 318 is defined for the data channel session 310 and may include ownership information 320 identifying one or more owners of the data channel, membership information 322 identifying members of the data channel and their respective permissions to interact with the data channel, and rules / settings for the data channel session 310.

[0068] Additionally, in the illustrated implementation, the data channel session accesses a channel media storage 316, which contains content to be shared via the data channel. In the illustrated implementation, the channel media storage 326 includes, for example, channel media 328, which includes various media / content items that have been shared via the data channel. In the illustrated implementation, this includes chat / game logs 330, images 352, and videos 334. It should be understood that other types of content / media may be shared via the data channel, as discussed in the present disclosure.

[0069] Also shown in the illustrated implementation is a network gaming service 330, which may include various server computers and / or gaming consoles that support console / cloud gaming services, enabling users to access and play video games, and associated communication and content generation services, such as audio / text chat services, screenshot / game play video saving and processing, etc. Content for data channels may result from interactions with the network gaming service 330, including game play interactions and user-to-user communication interactions, and thus, channel servers 308, and more specifically channel sessions, may receive content for their respective data channels from the network gaming service 330.

[0070] Figure 4 The transfer of ownership of a data channel 100 according to an implementation of the present disclosure is conceptually illustrated. In a typical case, a data channel 100 will have an owner, which is typically the user who initiated the data channel 100. For example, in the illustrated implementation, user A is the current owner of the data channel 100, and as the owner, manages the data channel 100, including controlling the membership and settings of the data channel 100. However, user A may no longer wish to manage the data channel 100. Therefore, in some implementations, user A can transfer ownership of the data channel 100 to another user. In the illustrated implementation, user A is conceptually illustrated as transferring ownership of the data channel 100 to user B, as indicated at reference numeral 400. In doing so, user A initiates a transaction to update the ownership information 320 (reference numeral 402) to reflect that user B is the owner of the data channel 100 and now has management rights with respect to the data channel 100.

[0071] Figure 5The revocation of access to a data channel 100 according to an implementation of the present disclosure is conceptually illustrated. In the illustrated implementation, user A is a channel owner with administrative rights to the data channel 100, and as conceptually illustrated at reference numeral 500, user A revokes user C's access to the data channel 100. To accomplish this, user A initiates a transaction to update the membership information 322 (reference numeral 502) of the data channel 100 so that user C is no longer granted access to the data channel 100. In some implementations, this entails changing the settings of the membership information 322 associated with user C (e.g., disabling user C's read / write permissions) so that the content of the data channel 100 is no longer published using user C's public key. In some implementations, user C's public key and / or other information is removed or deleted from the membership information.

[0072] Figure 6 Conceptually illustrates game-related communications / data transmitted via encrypted data channels according to implementations of the present disclosure. It should be understood that real-time activities occurring during a game session can be shared via encrypted data channels to protect user data privacy. In the illustrated implementation, a video game session 600 is performed, which defines the active game state of a video game played by multiple users 608, 610, 612, and 614. During the video game session 600, several associated communication and data services are provided for user interaction. As an example and not limitation, these such services may include the following: a text chat service 602 for text-based communications between users; an audio chat service 604 for audio communications between users (e.g., speech audio from a microphone associated with or operated by a user); a user camera sharing service 606 for sharing videos from a user's respective camera in the user's respective local environment (e.g., providing a user's own video so that others can see them); a game log service 606 that displays and records game activities / events so that users can better understand events that occurred during a video game session. For each of these services, as well as other services according to implementations of the present disclosure, data transmitted to and received from a user may be encrypted via data channel 100. Thus, sensitive data provided by associated services related to a video game session is processed to ensure user privacy and data protection.

[0073] Figure 7 Conceptually illustrates an interface for accessing content from a data channel according to an implementation of the present disclosure. In the illustrated implementation, the interface 700 is conceptualized as a content stream. The data channel may be named, as shown at reference numeral 702, and the owner of the data channel may be identified, as shown at reference numeral 704.

[0074] The current status of the members of the data channel is displayed in the member status section 706. For example, the member may be online, offline, participating in a game in progress, etc. It should be understood that the owner may have administrative rights and therefore may be able to add / remove users to / from the data channel, so that the user may or may not access the content stream of the data channel.

[0075] At reference numeral 708, a publishing interface is shown, enabling a user to publish comments or pictures or videos to a data channel content stream. In the content stream that is part of interface 700, various types of content may be present as shown. For example, at reference numeral 710, updates / notifications about gaming activity are shown, indicating that a gaming session is ongoing, and other relevant information, such as session duration and the ids of session participants. In some implementations, such content items may provide access to view more detailed information about a session and / or to watch live gameplay of a session.

[0076] Content item 712 is a posting of a video from a gaming session, including comments from the user who posted the video. Item 714 shows other users' reactions to item 712.

[0077] Content item 716 is a text post, in this case, a question to other users of data channel 100. It should be understood that users can post replies to item 716.

[0078] Although implementations according to the present disclosure have been described with reference to content originating from cloud gaming, it should be understood that the principles and implementations of the present disclosure may also be applied to content originating from console games, PC games, mobile device games, browser-based games, social media games, or video games executed in other types of devices and / or other types of contexts.

[0079] Fig. 8A 1 is a conceptual illustration of a process for initiating a cryptographically private player social data channel according to an implementation of the present disclosure. In the illustrated implementation, the owner 800 is establishing the data channel 100. The owner / administrator 800 generates a channel key K i To start the channel, as shown at reference numeral 802. The channel key K is encrypted using the owner's public key 804. i Encryption is performed (reference numeral 806), and the encrypted channel key E O (K i ) is stored in data channel 100.

[0080] Figure 8B The process for adding a participant to a data channel according to an implementation of the present disclosure is conceptually illustrated. 1(reference numeral 816) is added to the data channel 100, and the owner 800 uses the owner's private key 812 to decrypt (reference numeral 810) the encrypted channel key E O (K i ) to obtain the channel key K i . Then use participant P 1 The channel key K is encrypted (reference numeral 814) with the public key (reference numeral 818) of i As shown in the figure, participant P 1 The resulting encryption channel key E P1 (K i ) is stored in the data channel 100. Similarly, in order to store another participant P 2 (reference numeral 822) is added to the data channel 100, using the participant P 2 The public key (reference numeral 824) of the decrypted channel key K i Encryption is performed (reference numeral 820), and the participant P 2 The encrypted channel key E P2 (K i ) is stored in data channel 100.

[0081] It should be understood that when an owner / administrator starts a data channel and adds participants, encryption of the channel key occurs on the owner's device in a zero-trust manner, so the channel key and data encrypted using the channel key are not disclosed to any party other than the owner and participants. Therefore, even the network gaming service is unaware of the channel key and the encrypted data of the data channel. Therefore, the data channel can be maintained by the network gaming service and its systems, while the contents of the data channel are not exposed to the network gaming service because they are stored in encrypted form. The data channel makes the encryption key (E O (K i )、E P1 (K i )、E P2 (K i ) etc.), and when participants join, their encrypted channel keys are added to a channel list, which may be maintained by the network gaming service.

[0082] In some implementations, the channel key is symmetric (e.g., AES). In some implementations, the owner and participant keys are asymmetric (e.g., RSA, ECC, DS+EG).

[0083] Figure 8C The diagram conceptually illustrates the change of the channel list of encrypted channel keys for a data channel when a user leaves the data channel according to an implementation of the present disclosure. As shown in the figure, and according to the above implementation, for a user having an owner and a participant P1 and P 2 The data channel of the channel members generates the first channel key K 1 The channel key is encrypted with the member's public key, and the encrypted channel key is thus stored in the channel list 830A. As shown in the illustrated implementation, these include the channel keys for the owner, participant P, and 1 and participant P 2 The encryption channel key E O (K 1 )、E P1 (K 1 ) and E P2 (K 1 ).

[0084] When participant P 1 When leaving (or removing from the data channel), generate the second channel key K 2 , and is encrypted using the public keys of the remaining members of the data channel. In the implementation shown, for the owner and participant P respectively 2 , the encrypted channel key E O (K 2 ) and E P2 (K 2 ) are added to the channel list. These are encrypted channel keys (E O (K 1 )、E P1 (K 1 ) and E P2 (K 1 )). In this way, participant P 1 Still able to decrypt using the first channel key K 1 The old content / message is encrypted, but will not be decrypted using the second channel key K 2 Encrypted new content.

[0085] Continue to refer Figure 8C , consider another player P 3 In some implementations, the participant P 3 can be added to a data channel with full access to the entire history of the data channel, making participant P 3 Ability to view all historical contents of the data channel. In this case, the first and second channel keys K 1 and K 2 All new participants P 3 The public key is encrypted and used as the encrypted channel key E P3 (K 1 ) and E P3 (K 2) is added to the channel list, as shown in the channel list at reference numeral 830C.

[0086] However, in some implementations, participant P 3 A new contributor may be added to a data channel only, without access to the historical content of the data channel, but may access the content shared on the data channel after they join. In this case, a new third channel key K is generated. 3 , and with the owner and participant P 2 and P 3 The new encryption channel key E O (K 3 )、E P2 (K 3 ) and E P3 (K 3 ) is added to the channel list, as shown at reference numeral 830D.

[0087] Fig.8D A timeline is conceptually shown according to an implementation of the present disclosure, the timeline showing the content of a data channel based on Figure 8C In the implementation shown, in scenario A, participant P 1 Leave, and participant P 3 Join and have full access to the channel history. In scenario B, participant P 1 Leave, and participant P 3 Join but cannot access the history of the channel (but can access subsequent content). As shown at reference numeral 840, the initial owner creates a data channel and adds participants P 1 and P 2 At a later time, as shown at reference numeral 842, participant P 1 Afterwards, as shown at reference numeral 844, participant P 3 Add data channel.

[0088] In the illustrated implementation, in scenario A, after a channel is created and P 1 During the time period 846 between departures, the channel key K is initially used 1 Encrypt the channel. Then in P 1 During the time period 848 after leaving, the channel key K 2 Encrypt the channel. When participant P 3 When joining a channel, the channel key K is still used 2 Encrypt the channel.

[0089] In the scenario B shown, after the channel is created and P 1During the time period 850 between departures, the channel key K is also initially used. 1 Encrypt the channel. And in P 1 During the time period 852 after leaving, the channel key K 2 However, when participant P 3 When joining, in period 854, use the new channel key K 3 Encrypt the channel.

[0090] Fig. 8E Components of a message in a data channel 100 according to an implementation of the present disclosure are conceptually illustrated. A given message 860 is shown in the illustrated implementation as including an encrypted channel key 862, a message signature 864, and encrypted content 866. The encrypted channel keys 862 include all encrypted channel keys included in the channel list. It should be understood that the encrypted channel keys can only be decrypted by their respective private key holders, which are the owners and participants who have been authorized to access the data channel 100. As previously described, there can be multiple channel keys, and they can be encrypted using the public keys of different subsets of users.

[0091] Message 860 also includes a message signature 864. In some implementations, the message signature employs a symmetric signature algorithm (eg, HMAC (hash message authentication code based on hashing / keying), GMAC (Galois message authentication code), CMAC (cipher-based message authentication code)).

[0092] Message 860 also includes encrypted content 866, i.e., encrypted with channel key K i Encrypted message content. Content can include text, images, videos, etc.

[0093] In some implementations, the encrypted content 866 and the message signature 864 are generated simultaneously by the same process (e.g., using AES-GCM (Advanced Encryption Standard-Galois / Counter Mode).

[0094] Therefore, each message in the data channel includes the encrypted channel key, the message signature, and the encrypted message content. When a user (such as an owner or participant) receives a message, it parses the message to find the channel key encrypted with their public key and decrypts the channel key. The user can then use the decrypted channel key to decrypt the content of the message.

[0095] It should be understood that access to the message content is controlled via specific channel keys used to encrypt the content and by managing the encryption of the channel keys. The channel keys used to encrypt the content are encrypted using the public keys of specific users who will only be granted access to the content, and these encrypted keys are included in the message. Since the channel keys are transmitted only in encrypted form, only the corresponding private key holder can access the channel keys and decrypt the content. This provides a zero-trust solution from the user's perspective, and even the network game service cannot access the content because the network game service cannot decrypt the channel key. The network game service can store data channel metadata (but in encrypted form) and manage the channel (for example, by facilitating data communication between users). In addition, even if a given message is somehow intercepted or sent incorrectly by another party, the message content is safe because such a recipient will not be able to decrypt the channel key.

[0096] As described above, the resources of the network game service can be used to manage the data channel. For example, the network game service can maintain a channel list and distribute the channel list to the currently active members of the data channel as needed, such as when a member is removed (providing a new channel key to all remaining members as described above) or a new member is added (providing the channel list to the new member and updating the existing member to include the new encrypted channel key as described above). When members of the data channel generate messages, they can encrypt the content using the current channel key and can further concatenate the encryption key of the channel list. The messages can be transmitted to the data channel service / logic / handler of the network game service for storage and distribution to other users.

[0097] As described above, the implementation of the present disclosure can be applied to a cloud gaming system. An example of a cloud gaming system is Now cloud gaming system. In such a system, the client device can be a game console, such as 4 game console, or it may be another device such as a personal computer, laptop, tablet computer, mobile phone, mobile device, etc.

[0098] Broadly speaking, in order to implement cloud gaming, when a user request for a game title is received, several operations are performed by one or more servers in a data center associated with a cloud gaming site. When a cloud gaming site receives a user request, the data center hosting the game associated with the selected game title is identified, and the request is sent to the identified data center to instantiate the game for the selected game title. In response to the request, the server at the data center identifies the game code, loads the identified game code, and initializes files associated with the game code to prepare to present the game content to the user. The game data associated with the game may include general game data and user-specific game data. Therefore, the initialization file may include identifying, loading, and initializing both general game data and user-specific game data. Initializing general game data may include initializing a graphics engine, installing graphics data, initializing sound files, installing original images, and the like. Initializing user-specific data may include locating, transmitting, and installing user data, user history, game history, and the like.

[0099] When loading and initializing universal game data, a "startup" screen can be provided to render at the client device. A kind of startup screen can be designed to provide a representative image of the game being loaded, so as to allow the user to preview the type of the game being loaded. Once the universal game data is loaded, some initial content can be rendered, and a selection / navigation screen can be presented for user selection and customization. The user selection input provided at the selection / navigation screen may include game level selection, one or more game icon selections, game mode selections, game rewards, other user-related data that may need to upload additional game content. In some embodiments, game content is made available for viewing and interaction by streaming game content from the game cloud system to the user's computing device. In some implementations, after loading user-specific data, game content can be used to play games.

[0100] Fig.9AAn exemplary system for loading game files for games available through a cloud gaming site is shown. The system includes a plurality of client devices 900, which are communicatively connected to a cloud gaming site 904 via a network 902 (such as the Internet). When a request to access a cloud gaming site 904 is received from a client device 900, the cloud gaming site 904 accesses user account information 906 stored in a user data storage area 908 to identify the user associated with the client device that initiated the request. In some embodiments, the cloud gaming site can also verify the identified user to determine all games that the user is authorized to view / play. After user account identification / verification, the cloud gaming site accesses a game name data storage area 910 to identify the game name available at the game cloud site for the user account that initiated the request. The game name data storage area 910 then interacts with a game database 912 to obtain the game names of all games available for the cloud gaming site. When a new game is launched, the game database 912 will be updated with the game code, and the game name information of the newly launched game will be provided to the game name data storage area 910. When a request is made, the client device making the request may or may not be registered with the cloud gaming site. If the user of the client device making the request is not a registered user, the cloud gaming site may identify the user as a new user and select a game name suitable for the new user (e.g., a default set of game names). The identified game name is returned to the client device for presentation on display screen 900-a, such as Fig.9A shown.

[0101] Detect user interaction on one of the game names rendered on the client device, and send a signal to the cloud gaming site. The signal includes game name information in which the user interaction is detected and user interaction registered at the game name. In response to the signal received from the client device, the cloud gaming site actively determines the data center hosting the game, and sends a signal to the identified data center to load the game associated with the game name in which the user interaction is detected. In some embodiments, there may be more than one data center hosting the game. In such embodiments, the cloud gaming site can determine the geographic location of the client device that initiated the request, and identify a data center that is geographically close to the client device, and signal the data center to preload the game. The user's geographic location can be determined using a global positioning system (GPS) mechanism within the client device, the IP address of the client, the ping information of the client, etc. Of course, the aforementioned manner of detecting the user's geographic location can be exemplary, and other types of mechanisms or tools can be used to determine the user's geographic location. Identifying a data center close to the client device can minimize the delay during the user's interaction with the game. In some embodiments, the identified data center may not have the bandwidth / capacity required for hosting the game or may be overused. In these embodiments, the cloud gaming site can identify a second data center that is geographically close to the client device. Loading a game involves loading the game code and executing an instance of the game.

[0102] In response to receiving a signal from a cloud gaming site, the identified data center may select a server at the data center to instantiate a game on the server. The server is selected based on available hardware / software capabilities and game requirements. The server may include multiple game consoles, and the server may determine which of the multiple game consoles to use to load the game. The game console may be similar to an independent game console, or may be a rack server or a blade server. The blade server may then include multiple server blades, each of which has the circuitry required to instantiate a single dedicated application (such as a game). Of course, the above-mentioned game consoles are exemplary and should not be considered restrictive. Other types of game consoles (including game stations, etc.) and other forms of blade servers may also be used to host the identified games.

[0103] Once the game console is identified, the generic game-related code of the game is loaded onto the game console, and a signal identifying the game console instantiating the game is returned to the client device via the cloud gaming site over the network. Thus, the loaded game is available to the user.

[0104] Fig. 9B9 is a flowchart conceptually illustrating various operations performed for streaming a cloud video game to a client device according to an implementation of the present disclosure. The gaming system 918 executes the video game and generates raw (uncompressed) video 920 and audio 922. The video 920 and audio 922 are captured and encoded for streaming purposes, as indicated by reference numeral 924 in the illustrated figure. Encoding can be used for compression of video and audio streams to reduce bandwidth usage and optimize the gaming experience. Examples of encoding formats include H.265 / MPEG-H, H.264 / MPEG-4, H.263 / MPEG-4, H.262 / MPEG-2, WMV, VP6 / 7 / 8 / 9, etc.

[0105] The encoded audio 926 and the encoded video 928 are further packaged into network packets, as indicated by reference numeral 932, for transmission over a network (such as the Internet). The network packet encoding process can also employ a data encryption process to provide enhanced data security. In the illustrated implementation, as indicated by reference numeral 940, audio packets 934 and video packets 936 are generated for transmission over a network.

[0106] The gaming system 918 additionally generates haptic feedback data 930 , which is also packaged as a network data packet for network transmission. In the illustrated implementation, a haptic feedback data packet 938 is generated for transmission over the network, as further indicated at reference numeral 940 .

[0107] The above-mentioned operations of generating raw video and audio and tactile feedback data, encoding video and audio, and packaging the encoded audio / video and tactile feedback data for transmission are performed on one or more servers that jointly define the cloud gaming service / system. As indicated by reference numeral 940, audio, video, and tactile feedback data packets are transmitted over a network (such as and / or including the Internet). As indicated by reference numeral 942, audio data packet 934, video data packet 936, and tactile feedback data packet 938 are decoded / reorganized by the client device to define encoded audio 946, encoded video 948, and tactile feedback data 950 at the client device. If the data has been encrypted, the network data packet will also be decrypted. Then, as indicated by reference numeral 944, the encoded audio 946 and the encoded video 948 are decoded by the client device to generate client-side raw audio and video data for rendering on a display device 952. The tactile feedback data 950 can be processed / transmitted to produce a tactile feedback effect at a controller device 956 or other interface device that can render a tactile effect. An example of a haptic effect is vibration or rumbling of the controller device 956 .

[0108] It should be understood that the video game responds to user input and can therefore execute a program flow similar to the program flow described above for the transmission and processing of user input, but in the opposite direction from the client device to the server. As shown, the user operates the controller device 956 to generate input data 958. The input data 958 is packaged at the client device for transmission to the cloud gaming system over the network. The input data packet 960 is unpacked and reassembled by the cloud gaming server to define input data 962 on the server side. The input data 962 is fed to the gaming system 918, which processes the input data 962 to update the game state of the video game.

[0109] During the transmission of audio data packets 934, video data packets 936, and haptic feedback data packets 938 (reference numeral 940), data transmission through the network can be monitored to ensure the quality of service of the cloud game streaming. For example, network conditions, including both upstream and downstream network bandwidth, can be monitored as indicated by reference numeral 964, and game streaming can be adjusted in response to changes in available bandwidth. That is, encoding and decoding of network data packets can be controlled based on current network conditions, as indicated by reference numeral 966.

[0110] Fig.10 An implementation scheme of an information service provider architecture is shown. An information service provider (ISP) 1070 delivers a large number of information services to users 1082 that are geographically dispersed and connected via a network 1086. An ISP may deliver only one type of service, such as stock price updates, or may provide various types of services, such as broadcast media, news, sports, games, etc. In addition, the services provided by each ISP are dynamic, that is, services can be added or removed at any point in time. Therefore, the ISP that provides a particular type of service to a particular individual may change over time. For example, when a user is in her hometown, the user may be provided with services by an ISP close to the user, and when the user travels to a different city, the user may be provided with services by a different ISP. The hometown ISP will transfer the required information and data to the new ISP, so that the user information "follows" the user to the new city, thereby making the data closer to the user and easier to access. In another embodiment, a master-server relationship can be established between a main ISP that manages information for the user and a server ISP that interfaces directly with the user under the control of the main ISP. In another embodiment, when the client moves around the world, data is transferred from one ISP to another ISP so that the ISP that is in a better position to provide services to the user becomes the ISP that delivers these services.

[0111] ISP 1070 includes an application service provider (ASP) 1072, which provides computer-based services to customers over a network. Software provided using the ASP model is sometimes referred to as on-demand software or software as a service (SaaS). A simple form of providing access to a specific application, such as customer relationship management, is to use a standard protocol, such as HTTP. The application software resides on the vendor's system and is accessed by the user through a web browser using HTML, through dedicated client software provided by the vendor, or through other remote interfaces, such as a thin client.

[0112] Services delivered over a wide geographic area often use cloud computing. Cloud computing is a form of computing in which dynamically scalable and often virtualized resources are provided as a service over the Internet. Users do not need to be experts in the technical infrastructure that supports their "cloud". Cloud computing can be divided into different services, such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Cloud computing services typically provide common business applications accessed online from a web browser, while the software and data are stored on servers. Based on the way the Internet is depicted in computer network diagrams, the term cloud is used as a metaphor for the Internet (e.g., using servers, storage devices, and logic), and is an abstract concept for the complex infrastructure that it hides.

[0113] In addition, ISP 1070 includes a game processing server (GPS) 1074, which is used by game clients to play single-player and multi-player video games. Most video games played on the Internet are run by connection with a game server. Typically, games use a dedicated server application that collects data from players and distributes it to other players. This is more effective and efficient than a peer-to-peer arrangement, but it requires a separate server to host the server application. In another embodiment, GPS establishes communication between players, and the corresponding game of the player exchanges information without relying on a centralized GPS.

[0114] Dedicated GPS are servers that run independently of the clients. Such servers are usually run on dedicated hardware located in a data center, thus providing more bandwidth and dedicated processing power. For most PC-based multiplayer games, dedicated servers are the preferred method of hosting game servers. Massively multiplayer online games run on dedicated servers, which are usually hosted by the software company that owns the game title, allowing them to control and update the content.

[0115] The broadcast processing server (BPS) 1076 distributes the audio or video signal to the audience. Broadcasting to a very small range of viewers is sometimes called narrowcasting. The final leg of broadcast distribution is how the signal reaches the listener or observer, and it may be transmitted from the air to an antenna and receiver like a radio or television station, or it may be transmitted through cable television or cable broadcasting (or "wireless cable") through a workstation or directly from the network. The Internet can also bring radio or television to receivers, especially through multicasting, which allows sharing of signals and bandwidth. Historically, broadcasting has been defined by geographic areas, such as national broadcasting or regional broadcasting. However, with the popularity of fast Internet, broadcasting is not defined by geography, because content can reach almost any country in the world.

[0116] Storage Service Providers (SSPs) 1078 provide computer storage space and related management services. SSPs also provide periodic backup and archiving. By providing storage as a service, users can order more storage as needed. Another major advantage is that SSPs include backup services, and if a computer's hard drive fails, the user will not lose all of their data. In addition, multiple SSPs can have full or partial copies of a user's data, allowing the user to access the data in an efficient manner, regardless of the user's location or the device used to access the data. For example, a user can access personal files on a home computer as well as on a mobile phone (when the user is on the move).

[0117] Communications providers 1080 provide connectivity to users. One type of communications provider is an Internet Service Provider (ISP), which provides access to the Internet. An ISP connects its customers using data transmission technologies suitable for delivering Internet Protocol datagrams, such as dial-up, DSL, cable modem, fiber optic, wireless, or dedicated high-speed interconnects. Communications providers may also provide messaging services, such as email, instant messaging, and SMS text messages. Another type of communications provider is a Network Service Provider (NSP), which sells bandwidth or network access by providing direct backbone access to the Internet. Network service providers may include telecommunications companies, data carriers, wireless communications providers, Internet service providers, cable TV operators that provide high-speed Internet access, and the like.

[0118] Data exchange 1088 interconnects several modules within ISP 1070 and connects these modules to users 1082 via network 1086. Data exchange 1088 can cover a small area where all modules of ISP 1070 are in close proximity, or can cover a large geographic area when different modules are geographically dispersed. For example, data exchange 1088 can include Fast Gigabit Ethernet (or faster Gigabit Ethernet) within a cabinet in a data center, or an intercontinental Virtual Area Network (VLAN).

[0119] The user 1082 accesses the remote service using a client device 1084, which includes at least a CPU, memory, display, and I / O. The client device may be a PC, mobile phone, notebook computer, tablet computer, gaming system, PDA, etc. In one embodiment, the ISP 1070 identifies the type of device used by the client and adjusts the communication method used. In other cases, the client device uses a standard communication method (such as html) to access the ISP 1070.

[0120] Embodiments of the present disclosure may be practiced with various computer system configurations including handheld devices, microprocessor systems, microprocessor-based or programmable consumer electronics, minicomputers, mainframe computers, etc. The present disclosure may also be practiced in distributed computing environments where tasks are performed by remote processing devices that are linked through a wire-based or wireless network.

[0121] In view of the above embodiments, it should be understood that the present disclosure can adopt various computer-implemented operations involving data stored in a computer system. These operations are those operations that require physical manipulation of physical quantities. Any operation described herein that forms a part of the present disclosure is a useful machine operation. The present disclosure also relates to a device or equipment for performing these operations. The device can be specially constructed for the desired purpose, or the device can be a general-purpose computer selectively activated or configured by a computer program stored in the computer. Specifically, various general-purpose machines can be used together with computer programs written according to the teachings of this article, or it may be more convenient to construct more specialized equipment to perform the desired operations.

[0122] The present disclosure may also be embodied as computer-readable code on a computer-readable medium. Alternatively, the computer-readable code may be downloaded from a server using the above-mentioned data exchange interconnection. A computer-readable medium is any data storage device that can store data, which can then be read by a computer system. Examples of computer-readable media include hard drives, network attached storage devices (NAS), read-only memories, random access memories, CD-ROMs, CD-Rs, CD-RWs, magnetic tapes, and other optical and non-optical data storage devices. The computer-readable medium may include a computer-readable tangible medium distributed on a network-coupled computer system so that the computer-readable code is stored and executed in a distributed manner.

[0123] Although the method operations are described in a particular order, it should be understood that other housekeeping operations may be performed between the operations, or the operations may be adjusted so that they occur at slightly different times, or the operations may be distributed in a system that allows processing operations to occur at various intervals associated with the processing as long as the processing of the superimposed operations is performed in the desired manner.

[0124] Although the foregoing disclosure has been described in considerable detail for the purpose of clear understanding, it will be appreciated that certain changes and modifications may be practiced within the scope of the appended claims. Therefore, the present embodiments are to be considered illustrative rather than restrictive, and the disclosure is not to be limited to the details given herein, but may be modified within the scope and equivalent range of the described embodiments.

Claims

1. A method, comprising: Initiating a data channel through a network gaming service, including generating a channel key for encrypting content transmitted through the data channel, and generating a first encrypted channel key by encrypting the channel key using a public key associated with an owner of the data channel; adding a participant to the data channel, including generating a second encrypted channel key by encrypting the channel key using a public key associated with the participant; The message sent through the data channel includes encrypted content generated by encrypting the content of the message using the channel key, and the message also includes the first encrypted channel key and the second encrypted channel key.

2. The method of claim 1 , wherein after the user device associated with the owner receives the message, the channel key is decrypted from the first encrypted channel key using a private key associated with the owner, and the decrypted channel key is further used to decrypt the encrypted content of the message.

3. The method of claim 1 , wherein after a user device associated with the participant receives the message, the channel key is decrypted from the second encrypted channel key using a private key associated with the participant, and the decrypted channel key is further used to decrypt the encrypted content of the message.

4. The method of claim 1, further comprising: Removing the participant from the data channel includes generating a second channel key, and generating a third encrypted channel key by encrypting the second channel key using the public key associated with the owner.

5. The method of claim 4, wherein the second channel key is not encrypted with the public key associated with the participant.

6. The method of claim 1, further comprising: Adding a second participant to the data channel includes generating a third encrypted channel key by encrypting the channel key using a public key associated with the second participant.

7. The method of claim 6, wherein the message sent through the data channel further includes the third encryption channel key.

8. A method comprising: receiving a first encrypted channel key for the data channel from an owner device associated with an owner of the data channel over a network, the first encrypted channel key being a channel key encrypted with a public key associated with the owner of the data channel, the channel key being used to encrypt content shared via the data channel; receiving one or more secondary encrypted channel keys from the owner device over the network, each secondary encrypted channel key being the channel key encrypted with a public key associated with a respective participant of the data channel; storing the first encrypted channel key and the one or more secondary encrypted channel keys in a channel list; distributing the channel list to one or more participant devices respectively associated with each participant of the data channel via the network; The communication on the data channel includes the first encryption channel key, the secondary encryption channel key and the content encrypted using the channel key.

9. A non-transitory computer-readable medium having program instructions embodied thereon, the program instructions, when executed by at least one processor, causing the at least one processor to perform a method comprising: Initiating a data channel through a network gaming service, including generating a channel key for encrypting content transmitted through the data channel, and generating a first encrypted channel key by encrypting the channel key using a public key associated with an owner of the data channel; adding a participant to the data channel, including generating a second encrypted channel key by encrypting the channel key using a public key associated with the participant; The message sent through the data channel includes encrypted content generated by encrypting the content of the message using the channel key, and also includes the first encrypted channel key and the second encrypted channel key.