The lifetime of local authentication is a security and usability choice. An old success result should not grant unlimited authority.
Evaluation approach
Define which operations require fresh verification. Reassess after backgrounding, account changes and sensitive-setting updates.
Application example
Returning to a document list may use an existing session while exporting requires reauthentication. Make the approved action clear.
Limits and considerations
Biometric success does not remove server session-expiry or authorization checks.
How long is approval valid?
Consider action type and content as well as elapsed time. Recent authentication need not authorize every later sensitive action; new recipients or exports may warrant separate approval.
Checks and decisions
- Separate sensitive operations
- Define context lifetime
- Test switching
Sources
The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.