4.3.3. Protection for the integrity of user session
In the first handshaking of Phase IV, the user session is encrypted with the private key MN_Prv of the master node. An attacker, who has listened to the communication between the master node and the CA server or has obtained the public key of the CA server, may be able to decrypt the user session. However, after Phase IV the user session is encrypted with the encryption information {SCA, SC_Key} determined by the slave node. Since the attacker could not have the knowledge of the encryption information, he is hence not able to encrypt the user session to perform an attack. On the other hand, if the attacker has altered the user session, the verification of the user session in the second handshaking step of Phase IV cannot pass through. The modification can be easily detected by the master node. Therefore, the first and second handshaking with encrypted user session ensure the integrity of the user session.