V6.7.1: Verify that the certificates used to verify cryptographic authentication assertions are stored in a way protects them from modification.
ASVS Maturity
V6.7.2
V6.7.2: Verify that the challenge nonce is at least 64 bits in length, and statistically unique or unique over the lifetime of the cryptographic device.