Skip to main content

Define out of band token lifespan

Requirement#

The system must expire out of band authentication requests, codes or tokens after 10 minutes and should only allow them to be used once within this period.

Description#

Secure out of band authenticators are physical devices that can communicate with an authentication verifier over a secure secondary channel. They serve as an additional security measure for identity assertion during authentication processes or sensitive transactions. Systems should expire out of band tokens after 10 minutes and allow them to be used only once within this period to prevent replay attacks.

References#