Dual Expiry security improvements

Hello.


We're currently implementing "Renting and Leasing the Content Key" functionality for our mobile application. As per FairPlay Streaming Programming Guide v4.1.0, pages 37-38, Table 5-1, incoming SPC will have a Media Playback State TLLV.


Although specification say nothing about actions that must be taken we're wondering if any might be taken for better security. Would you mind providing any best practices how one might take care of Creation date or another field for better security? E.g. does it make any sense to verify that the given timestamp in Creation Date field isn't too old?