A method and system that protects against a replay attack in a closed
system postage meter is provided. "Freshness" data is included along with
each indicium message sent from the meter to the printer, thereby
enabling the printer to detect "stale" indicium data, i.e., indicium data
that was previously generated and is being replayed, and prohibit the
printing of duplicate indicia. The freshness data includes a random nonce
generated by the printer during initialization along with sequence data
that the printer can verify against sequence data from the previous
printed indicium. If in the current indicium message the nonce is
different or the current sequence data is not greater than or equal to
the sequence data from the previous printed indicium, indicating the
current indicium data may have been previously generated and is a replay,
the printer will not print the current indicium data.