The Provider must provide successful direct verification exactly once. A second attempt at direct verification will be attempted and that must be denied to protect against replay attacks.