Identity authentication method and system based on CPU-GPU heterogeneity

By adopting the CPU-GPU heterogeneous computing platform in the PAKE protocol to offload computationally intensive operations, the performance bottleneck and integration difficulties of the PAKE protocol in high-concurrency Web services are solved, efficient identity authentication and key negotiation are achieved, and the system's processing capabilities and user experience are improved.

CN120639340APending Publication Date: 2025-09-12UNIV OF CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510642448.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

The existing PAKE protocol faces the problems of high computing overhead, difficulty in supporting high-concurrency Web service scenarios, and high integration and operation and maintenance costs in actual deployment.

Method used

It adopts a CPU-GPU heterogeneous computing platform, offloads computationally intensive operations through the PAKE server, utilizes the massive parallel processing capabilities of the GPU, and combines it with an asynchronous processing architecture to optimize computational load distribution and interactive data flow, simplifying system integration.

Benefits of technology

It significantly improves the processing performance of the PAKE protocol, supports high-concurrency scenarios, reduces integration complexity and cost, and improves system throughput and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639340A_ABST
    Figure CN120639340A_ABST
Patent Text Reader

Abstract

The invention discloses an identity authentication method and system based on CPU-GPU heterogeneity, and belongs to the technical field of cryptology. In order to solve the problems of performance bottleneck and system integration difficulty existing when a password authentication key exchange protocol relates to computation-intensive operations such as OPRF and AKE, computation load optimization distribution and asynchronous parallel processing means under a CPU-GPU heterogeneous architecture are mainly adopted, and efficient acceleration of a re-computation task in the PAKE protocol is achieved. According to the method, the authentication protocol processing performance can be remarkably improved, high concurrent access is supported, and the integration complexity in an existing Web system is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of cryptography, and in particular relates to an identity authentication method and system based on CPU-GPU heterogeneity. Background Art

[0002] The internet's identity authentication system has long relied on a password-based authentication mechanism. Its core process involves transmitting user passwords to the server via an SSL / TLS channel, where they are processed using a slow hash function and then compared with a stored hash value (or salted hash) for verification. Although this mechanism has been widely used, its inherent security flaws are becoming increasingly prominent. On the one hand, the server needs to store passwords or their hash values, making them a prime target for attackers. Once the database is compromised or an internal leak occurs, attackers can quickly crack low-entropy passwords through offline dictionary attacks. On the other hand, this mechanism relies heavily on the channel security of SSL / TLS, which in turn is subject to the reliability of the PKI system and is vulnerable to threats such as private key leakage and certificate forgery. Even within a trusted TLS channel, passwords may still be transmitted in plaintext within the internal network after being decrypted by the gateway, exposing them to the risk of passive eavesdropping.

[0003] To address the above issues, researchers proposed the Password Authenticated Key Exchange (PAKE) protocol, which enables the communicating parties to negotiate a high-strength session key based on a low-entropy password, and prevents the password from appearing in plain text or reconstructible form during the authentication process. The PAKE protocol is divided into a symmetric type (bPAKE) and an asymmetric type (aPAKE) that is more suitable for the client-server model. A major advantage of aPAKE is that the server only needs to save an irreversible mapping based on the password (similar to a "public key"), and even if it is attacked, the user password cannot be directly restored, thereby significantly improving security. At the same time, this type of protocol has good resistance to man-in-the-middle attacks and passive eavesdropping.

[0004] In recent years, the demand for higher security has led to the emergence of aPAKE protocol designs that combine the oblivious pseudorandom function (OPRF) with authenticated key exchange (AKE). The OPAQUE protocol, a representative solution, has been recommended by the IRTF's CFRG as the standard aPAKE protocol and recommended for inclusion in the IETF protocol architecture. By integrating OPRF into the authentication process to process user passwords, this protocol effectively improves its ability to resist advanced threats such as pre-computation attacks.

[0005] However, despite the significant theoretical advantages of the aPAKE protocol, it still faces multiple challenges in practical deployment. First, the protocol involves multiple complex cryptographic primitives, and the computational overhead is much higher than traditional authentication processes. This makes it difficult to support high-concurrency Web service scenarios, which can easily lead to increased authentication latency and decreased system throughput. Second, existing systems are generally built based on the TLS+hash mechanism. Migrating to the PAKE system requires a deep reconstruction of the authentication process, storage structure, and server logic, resulting in high integration and operation and maintenance costs. Therefore, the promotion of the PAKE protocol in engineering practice is still limited by performance bottlenecks and deployment costs. There is an urgent need for a technical solution that can effectively alleviate these problems. Summary of the Invention

[0006] In order to solve the technical problems of performance bottlenecks and system integration difficulties faced by the password-authenticated key exchange protocol in the prior art when it includes computationally intensive operations such as OPRF and AKE, the present invention provides an identity authentication method and system based on CPU-GPU heterogeneity. The method aims to significantly improve the protocol processing performance, support high-concurrency application scenarios, and reduce its integration complexity in existing Web systems by optimizing computing load distribution and utilizing the parallel processing capabilities of heterogeneous hardware.

[0007] In order to achieve the above object, the technical solution adopted by the present invention is as follows:

[0008] A CPU-GPU heterogeneous identity authentication method includes the following steps:

[0009] 1) The client performs the initial calculation of the PAKE protocol client based on the identity ID and password π entered by the user;

[0010] 2) After receiving the first request message from the client, the Web server forwards the data required for the server-side recalculation load to the PAKE server;

[0011] 3) The PAKE server uses an asynchronous processing mode to receive and manage request tasks, uses CPU-GPU heterogeneous computing resources to perform computationally intensive server-side operations in the PAKE protocol, and returns the computation results to the Web server;

[0012] 4) The Web server generates an authentication response based on the calculation result returned by the PAKE server and the client information, and sends it to the client;

[0013] 5) The client completes key negotiation and confirmation calculation, encapsulates the confirmation information into a second authentication request, and sends it to the Web server;

[0014] 6) The Web server verifies the validity of the client confirmation information and completes the PAKE protocol authentication process.

[0015] Furthermore, step 1) specifically includes the following steps:

[0016] The client performs the initial operation of the OPRF phase, blinds the password π entered by the user, and generates the client OPRF request data Req oprf ;

[0017] The client performs the initial calculation of the AKE phase and generates a temporary public key P C,eph And client random number Nonce C The first request message;

[0018] The client sends the user ID, Req oprf And the AKE first request message is encapsulated as a first authentication request and sent to the Web server.

[0019] Furthermore, step 2) specifically includes the following steps:

[0020] After receiving the first authentication request, the web server retrieves the server-side PAKE credential information corresponding to the user from the database based on the ID, including the server OPRF key material and other server-side confidential information required in the AKE phase;

[0021] The web server forwards the data required to perform the server-side heavy computing load to the PAKE server;

[0022] The web server temporarily stores the remaining components and context data in the client request for subsequent authentication processing.

[0023] Furthermore, step 3) specifically includes the following steps:

[0024] The I / O processing module of the PAKE server uses an I / O event notification mechanism and multiple I / O threads to monitor and receive network connections and request data from the Web server;

[0025] The PAKE server parses and encapsulates the received requests into computing tasks and puts them into the task queue, thus decoupling I / O operations from computing tasks.

[0026] The dispatch thread extracts pending tasks from the task queue and assigns them to the backend work module according to the preset scheduling strategy;

[0027] The work module has dynamic scheduling capabilities based on task batch thresholds, scheduling tasks that meet batch processing conditions to the GPU for parallel acceleration processing, and scheduling tasks that do not meet batch processing conditions or are delay-sensitive to the CPU for processing;

[0028] After the PAKE server completes the server-side OPRF calculation and AKE recalculation load processing, it returns the calculation results to the Web server.

[0029] Furthermore, step 4) specifically includes the following steps:

[0030] After receiving the calculation result returned by the PAKE server, the Web server combines the client-side AKE parameters with the server-side AKE parameters to generate the server-side AKE response message;

[0031] The web server executes the key derivation function (KDF) to generate the session key K;

[0032] The Web server generates the server-side AKE confirmation message M server ;

[0033] The Web server sends the server OPRF calculation result, AKE response message and AKE confirmation information M server Encapsulates the first authentication response and sends it back to the client.

[0034] Furthermore, step 5) specifically includes the following steps:

[0035] The client completes the final calculation of the OPRF phase based on the received OPRF calculation results;

[0036] The client executes the key derivation function to generate the session key K;

[0037] Client verifies server confirmation information M server effectiveness;

[0038] If the verification is successful, the client generates its own AKE confirmation information M client ;

[0039] The client will generate the confirmation message M client Encapsulate it into a second authentication request and send it to the Web server.

[0040] Furthermore, step 6) specifically includes the following steps:

[0041] After receiving the second authentication request from the client, the web server verifies the client confirmation information M based on the temporarily stored context information. client effectiveness;

[0042] If the verification is successful, the PAKE protocol authentication process is completed and a secure communication session is established.

[0043] A CPU-GPU heterogeneous identity authentication system, used to execute the above method, includes:

[0044] Client: Configures the client logic for executing the PAKE protocol, including: performing the blinding and final calculations of the OPRF phase; performing the initial request generation, key derivation, and confirmation information generation of the AKE phase; constructing and sending the first and second authentication requests; verifying the server's confirmation information; and establishing the session key.

[0045] Web server: configured to coordinate the authentication interaction process between the client and the PAKE server, including: receiving the client's first authentication request and the second authentication request; retrieving the user's corresponding PAKE credentials from the database; temporarily storing the client's AKE parameters and context information; forwarding the computationally intensive workload data to be executed to the PAKE server; receiving the calculation results from the PAKE server, generating an AKE response message and confirmation information, and executing the key derivation function; verifying the client's AKE confirmation information, and completing the PAKE protocol;

[0046] PAKE server: As an independent computing node, it communicates with the web server and is equipped with heterogeneous computing resources consisting of CPU and GPU. Its functions include: receiving authentication computing requests from the web server; implementing efficient request reception and management through the I / O processing module; placing requested tasks into the task queue to decouple computing tasks from I / O; using the scheduling module to dynamically allocate tasks based on batch size, scheduling large batch tasks to the GPU for parallel processing and small batch or low-latency tasks to the CPU for processing; executing the server-side OPRF calculation and AKE recalculation tasks in the PAKE protocol; and returning the calculation results to the web server.

[0047] Database: Configured to store the user's server-side PAKE credential data, including: the user's corresponding server OPRF key material; other server-side confidential information required for the AKE phase; support high-concurrency retrieval operations to cooperate with the Web server to quickly access authentication data.

[0048] Compared with the prior art, the present invention has the following beneficial effects:

[0049] 1. This invention offloads computationally intensive server-side operations in the PAKE protocol to a dedicated PAKE server built on a CPU-GPU heterogeneous computing platform. This fully leverages the massively parallel processing capabilities of the GPU, significantly improving the processing performance of the PAKE protocol and supporting the needs of high-concurrency scenarios.

[0050] 2. The PAKE server of the present invention adopts an efficient asynchronous processing architecture, which can dynamically dispatch tasks to the CPU or GPU for processing according to the real-time load situation, realizing intelligent optimization of resource utilization and taking into account high throughput and low latency;

[0051] 3. This invention reduces the authentication interaction between the client and the Web server to two rounds by optimizing the interactive data flow, thus improving overall efficiency and user experience.

[0052] 4. This invention offloads the core heavy computation load of the PAKE protocol from the Web server to an independent PAKE server for execution, simplifying the integrated deployment of the PAKE protocol in existing Web systems and reducing the cost of migrating enterprises to the PAKE framework;

[0053] 5. This invention fully leverages the theoretical advantages of the PAKE protocol in identity authentication and key negotiation, transforming them into practical engineering value, and providing a high-performance, easily integrated solution for the field of network security. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 This is the overall architecture diagram of the CPU-GPU heterogeneous identity authentication based on the present invention.

[0055] Figure 2 This is the interactive data flow diagram of the CPU-GPU heterogeneous identity authentication of the present invention. DETAILED DESCRIPTION

[0056] In order to make the purpose, technical solutions and advantages of the present invention clearer, the present invention is further described in detail with reference to specific embodiments. It should be understood that the specific embodiments herein are only used to illustrate the present invention and are not intended to limit the scope of protection of the present invention.

[0057] The embodiment of the present invention provides a method and system for identity authentication based on CPU-GPU heterogeneity, such as Figure 1 and Figure 2 As shown in the figure, it aims to provide a high-performance and easy-to-integrate deployment solution for the modern PAKE protocol including the OPRF phase and the AKE phase.

[0058] 1. Methods

[0059] An embodiment of the present invention proposes a CPU-GPU heterogeneous identity authentication method that optimizes the authentication interaction between the client and the Web server into two rounds, including the following steps:

[0060] The first round of interaction: The client initiates, the server processes and responds:

[0061] Step 1: The client prepares and sends a request: The user enters the ID and password π. The client performs local calculations and generates the client OPRF request data Req oprf , client AKE first request message (P C,eph ,Nonce C ) authentication request is sent to the Web server. The specific steps include:

[0062] 1.1: Blind the password and generate the client OPRF request data Req oprf ;

[0063] 1.2: Generate the client's first AKE request message, including the temporary public key P C,eph And the client random number Nonce C ;

[0064] 1.3: Change ID, Req oprf The AKE first request message is encapsulated as a first authentication request and sent to the Web server.

[0065] Step 2: The Web server receives and dispatches tasks: The Web server receives the request and queries the database to obtain the server-side PAKE credential information corresponding to the user. oprf ,K S,oprf ,P C,eph ,P C,static ) is sent to the PAKE server.

[0066] The specific steps include:

[0067] 2.1: Query the database to obtain the server-side OPRF key K S,oprf and other confidential information, including the client's long-term public key P C,static ;

[0068] 2.2: Authentication related parameters (including Req oprf ,P S,oprf ,P C,eph ,P C,static ) is packaged and forwarded to the PAKE server to offload computationally intensive tasks.

[0069] Step 3: PAKE server asynchronous batch processing: The PAKE server receives requests asynchronously. Based on the current load and scheduling strategy (threshold-based CPU / GPU selection and batch processing), the server OPRF result Res is calculated. oprf , generate server AKE temporary public key P S,eph After the calculation is completed, (Res oprf ,P S,eph The calculation result of the PRK is returned to the web server, where the PRK (Pseudorandom Key) is the intermediate key material used by the subsequent KDF. The specific steps include:

[0070] 3.1: Receive the authentication request from the Web server through the I / O processing module;

[0071] 3.2: Parse the authentication request into a computing task and put it into the task queue;

[0072] 3.3: The distribution thread dispatches tasks to the CPU or GPU based on the current load and task type;

[0073] 3.4: For tasks with large batches, GPU parallel processing is used; for delay-sensitive or small batch tasks, CPU processing is used;

[0074] 3.5: Perform server OPRF calculation and AKE recalculation to generate server OPRF response Res oprf , server temporary public key P S,eph and intermediate key PRK;

[0075] 3.6: Return the calculation results asynchronously to the web server.

[0076] Step 4: The web server completes the calculation and constructs a response: After receiving the result from the PAKE server, the web server generates a Nonce S , perform the final server-side key derivation and server confirmation information generation. Then, (Res oprf ,P S,eph ,Nonce S ,M server ) is sent back to the client as the first round of response. The specific steps include:

[0077] 4.1: Generate server random number Nonce S ;

[0078] 4.2: Call the key derivation function (KDF) to generate the final session key K;

[0079] 4.3: Generate server-side confirmation information M server ;

[0080] 4.4: The first round response (Res oprf ,P S,eph ,Nonce S ,M server ) is sent to the client.

[0081] Second round of interaction: client processing, sending confirmation, server verification:

[0082] Step 5: The client processes the response and generates a confirmation: The client receives the response, generates a session key K, and verifies that the server confirms M server If passed, client confirmation information M is generated client , sent to the Web server. The specific steps include:

[0083] 5.1: Use the server response to complete the final calculation of the OPRF stage;

[0084] 5.2: Generate the final session key K;

[0085] 5.3: Verify the server confirms the information M server effectiveness;

[0086] 5.4: If the verification is successful, generate client confirmation information M client ;

[0087] 5.5: M client Sent to the web server as the second round of requests.

[0088] Step 6: After receiving the second round of requests, the web server verifies the client confirmation information M client The validity of the PAKE protocol is completed.

[0089] 2. System part

[0090] To implement the above method, an embodiment of the present invention also provides a CPU-GPU heterogeneous identity authentication system, comprising a client, a web server, a PAKE server, and a database. This system is designed to offload the computationally heavy server-side cryptographic operations in the PAKE protocol from the web server to a dedicated PAKE server built on a CPU-GPU heterogeneous computing platform, while optimizing interactive data flows. The system is described in detail below:

[0091] 1. Client (Client / Browser): User interaction terminal, such as a web browser; embedded with PAKE protocol client logic code, executes PAKE protocol client logic, specifically including:

[0092] Execution in the OPRF phase: Blind the user password π and generate the client OPRF request data Req oprf ;

[0093] Execution in the AKE phase: Generate the client's first AKE request message, including the temporary public key P C,eph and client Nonce C ; Send the first round of requests to the Web server, including ID, OPRF request data, and AKE first request message; After receiving the server response, perform message deblinding and complete the final OPRF calculation; Generate the session key K based on the server response message and related context; Verify the server confirmation information M server ; Generate client confirmation information M client ; Send the second round of requests to the Web server, including M client .

[0094] 2. Web Server: Web application server and protocol coordination center, specifically performs the following operations:

[0095] Receive the first round of requests from the client;

[0096] Query the database to obtain the server OPRF key material K S,oprf and other server-side confidential information, including the client's long-term public key P C,static ;

[0097] Offload computing tasks: client OPRF request data Req oprf , K S,oprf , client temporary public key P C,eph , client long-term public key P C,static Send to PAKE server;

[0098] Receive the calculation results returned by the PAKE server;

[0099] Perform subsequent server-side calculations: Generate server-side Nonce S , use the relevant parameters to execute KDF to generate the session key K, and generate the server confirmation information M server ;

[0100] Send the first round of response to the client, including (Res oprf ,P S,eph ,Nonce S ,M server );

[0101] Receive the second round of client requests (M client );

[0102] Perform final verification: Verify M client effectiveness.

[0103] 3. PAKE Server: As the core acceleration engine of this system, it communicates efficiently with the web server through the internal network. It is equipped with a heterogeneous computing platform composed of high-performance CPUs and GPUs and deploys an optimized algorithm for the core heavy computing load of the PAKE protocol. It performs the following operations:

[0104] (1) Implementing an efficient asynchronous working mode: To effectively handle a large number of concurrent requests and fully utilize heterogeneous computing resources, a sophisticated asynchronous processing architecture is built within the PAKE server. This architecture typically includes:

[0105] I / O processing module: This module uses an efficient I / O event notification mechanism (such as Linux epoll) and multiple I / O threads to monitor and receive network connections and request packets from the Web server.

[0106] Task queue: The I / O thread parses and encapsulates received requests into computing tasks and places them into one or more shared task queues, decoupling I / O processing from computing processing.

[0107] Distributing threads: Multiple distributing threads obtain pending computing tasks from the task queue;

[0108] Asynchronous task execution and scheduling: The dispatch thread does not execute tasks immediately, but instead dispatches tasks to backend work modules based on a pre-set strategy. This asynchronous processing method allows the server to continuously receive requests at high concurrency while aggregating tasks to improve processing efficiency.

[0109] (2) Execute the offloaded heavy computation load task, including OPRF calculation and AKE heavy computation load part;

[0110] (3) Implement heterogeneous scheduling and GPU batch processing, including:

[0111] The distribution thread dynamically schedules tasks to the CPU or GPU work module based on the task type and real-time load;

[0112] GPU Batch Processing: For computationally intensive tasks suitable for GPU parallel processing, the dispatch thread aggregates a certain number of tasks taken from the queue into a batch. When the number of aggregated tasks reaches or exceeds the preset threshold, the batch of tasks will be submitted to the GPU, which will use its numerous computing cores for large-scale parallel processing.

[0113] Row processing to achieve high throughput;

[0114] CPU processing: Tasks with a small number of tasks (below the threshold) or tasks that are not suitable for large-scale parallel processing are scheduled to the CPU for processing;

[0115] Through this threshold-based dynamic scheduling strategy, the system can automatically select the optimal computing resources under different load conditions, balancing high throughput and low latency.

[0116] (4) The calculation results are notified and returned to the Web server asynchronously.

[0117] 4. Database:

[0118] Stores user information and server-side credentials required by the PAKE protocol, such as K S,oprf and P C,static .

[0119] Experimental test:

[0120] The technical solution of the present invention was experimentally tested, and the PAKE server in the test environment was configured with Core(TM) i9 series CPU and NVIDIA GeForce GTX TITAN V GPU. Experimental test results show that the password-authenticated key exchange protocol using the acceleration framework of the present invention can achieve a high processing throughput of 1080.98Kop / S. In high-concurrency scenario testing on three mainstream browsers, Chrome, Firefox, and Edge, the total end-to-end authentication latency was 317ms, 301ms, and 323ms, respectively. Compared with traditional hash-based authentication mechanisms, the present invention significantly enhances security while maintaining a similar level of authentication latency.

[0121] In summary, this invention effectively shares the computational load and optimizes protocol interaction rounds by offloading computationally intensive PAKE server-side operations to a dedicated heterogeneous computing server, PAKE-Server, while the web server handles key derivation and verification, which require a full context. This significantly improves the system's ability to handle highly concurrent PAKE authentication requests, improves the user experience by reducing client latency, and provides a more feasible technical path for integrating advanced PAKE protocols into existing web systems.

[0122] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The description and examples are to be considered merely as exemplary, and the present disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof.

Claims

1. A CPU-GPU heterogeneous identity authentication method, characterized in that: The following steps are involved: 1) The client performs the initial calculation of the PAKE protocol client based on the identity ID and password π entered by the user; 2) After receiving the first request message from the client, the Web server forwards the data required for the server-side recalculation load to the PAKE server; 3) The PAKE server uses an asynchronous processing mode to receive and manage request tasks, uses CPU-GPU heterogeneous computing resources to perform computationally intensive server-side operations in the PAKE protocol, and returns the computation results to the Web server; 4) The Web server generates an authentication response based on the calculation result returned by the PAKE server and the client information, and sends it to the client; 5) The client completes key negotiation and confirmation calculation, encapsulates the confirmation information into a second authentication request, and sends it to the Web server; 6) The Web server verifies the validity of the client confirmation information and completes the PAKE protocol authentication process.

2. The method according to claim 1, wherein Step 1) specifically includes the following steps: The client performs the initial operation of the OPRF phase, blinds the password π entered by the user, and generates the client OPRF request data Req oprf ; The client performs the initial calculation of the AKE phase and generates a temporary public key P C,eph And client random number Nonce C The first request message; The client sends the user ID, Req oprf And the AKE first request message is encapsulated as a first authentication request and sent to the Web server.

3. The method according to claim 2, wherein Step 2) specifically includes the following steps: After receiving the first authentication request, the web server retrieves the server-side PAKE credential information corresponding to the user from the database based on the ID, including the server OPRF key material and other server-side confidential information required in the AKE phase; The web server forwards the data required to perform the server-side heavy computing load to the PAKE server; The web server temporarily stores the remaining components and context data in the client request for subsequent authentication processing.

4. The method according to claim 3, wherein Step 3) specifically includes the following steps: The I / O processing module of the PAKE server uses an I / O event notification mechanism and multiple I / O threads to monitor and receive network connections and request data from the Web server; The PAKE server parses and encapsulates the received requests into computing tasks and puts them into the task queue, thus decoupling I / O operations from computing tasks. The dispatch thread extracts pending tasks from the task queue and assigns them to the backend work module according to the preset scheduling strategy; The work module has dynamic scheduling capabilities based on task batch thresholds, scheduling tasks that meet batch processing conditions to the GPU for parallel acceleration processing, and scheduling tasks that do not meet batch processing conditions or are delay-sensitive to the CPU for processing; After the PAKE server completes the server-side OPRF calculation and AKE recalculation load processing, it returns the calculation results to the Web server.

5. The method according to claim 4, wherein Step 4) specifically includes the following steps: After receiving the calculation result returned by the PAKE server, the Web server combines the client-side AKE parameters with the server-side AKE parameters to generate the server-side AKE response message; The web server executes the key derivation function to generate the session key K; The Web server generates the server-side AKE confirmation message M server ; The Web server sends the server OPRF calculation result, AKE response message and AKE confirmation information M server Encapsulates the first authentication response and sends it back to the client.

6. The method according to claim 5, wherein Step 5) specifically includes the following steps: The client completes the final calculation of the OPRF phase based on the received OPRF calculation results; The client executes the key derivation function to generate the session key K; Client verifies server confirmation information M server effectiveness; If the verification is successful, the client generates its own AKE confirmation information M client ; The client will generate the confirmation message M client Encapsulate it into a second authentication request and send it to the Web server.

7. The method according to claim 6, wherein Step 6) specifically includes the following steps: After receiving the second authentication request from the client, the web server verifies the client confirmation information M based on the temporarily stored context information. client effectiveness; If the verification is successful, the PAKE protocol authentication process is completed and a secure communication session is established.

8. A CPU-GPU heterogeneous identity authentication system, used to execute the method according to any one of claims 1 to 7, characterized in that: include: Client: Configures the client logic for executing the PAKE protocol, including: performing the blinding and final calculations of the OPRF phase; performing the initial request generation, key derivation, and confirmation information generation of the AKE phase; constructing and sending the first and second authentication requests; verifying the server's confirmation information; and establishing the session key. Web server: configured to coordinate the authentication interaction process between the client and the PAKE server, including: receiving the client's first authentication request and the second authentication request; retrieving the user's corresponding PAKE credentials from the database; temporarily storing the client's AKE parameters and context information; forwarding the computationally intensive workload data to be executed to the PAKE server; receiving the calculation results from the PAKE server, generating an AKE response message and confirmation information, and executing the key derivation function; verifying the client's AKE confirmation information, and completing the PAKE protocol; PAKE server: As an independent computing node, it communicates with the web server and is equipped with heterogeneous computing resources consisting of CPU and GPU. Its functions include: receiving authentication computing requests from the web server; implementing efficient request reception and management through the I / O processing module; placing requested tasks into the task queue to decouple computing tasks from I / O; using the scheduling module to dynamically allocate tasks based on batch size, scheduling large batch tasks to the GPU for parallel processing and small batch or low-latency tasks to the CPU for processing; executing the server-side OPRF calculation and AKE recalculation tasks in the PAKE protocol; and returning the calculation results to the web server. Database: Configured to store the user's server-side PAKE credential data, including: the user's corresponding server OPRF key material; other server-side confidential information required for the AKE phase; support high-concurrency retrieval operations to cooperate with the Web server to quickly access authentication data.