Set the
Lifetime
to
two years or less, depending on how many encryptions the device
performs. The more encryptions a device performs, the shorter the
Lifetime
you
should set. The critical consideration is to not run out of unique encryptions
before you change the master key. Each master key can provide up to
2
32
unique encryptions based on the master key value
and the Initialization Vector (IV) value. After 2
32
unique
encryptions, encryptions repeat (are no longer unique), which is
a security risk.