Efficient solution to verify kernel uniqueness + better absolute timelocks

See my (edited) reply in Replay Attacks and possible mitigations - #115 by tromp