Set the Lifetime to two years or less, depending
on how many encryptions the device performs. The more encryptions a
device performs, the shorter the Lifetime you
should set. The critical consideration is to not run out of unique
encryptions before you change the master key. Each master key can
provide up to 232 unique encryptions based on the master key
value and the Initialization Vector (IV) value. After 232
unique encryptions, encryptions repeat (are no longer unique), which is
a security risk.
Set a Time for Reminder value (see next step) for
the master key and when the reminder notification occurs, change the
master key.