e key in previous epochs. In 1997 I proposed the obvious extension to digital signatures, in order to prevent the retrospective forgery of messages signed using keys belonging to earlier epochs but without requiring that the public key infrastructure accommodate large numbers of time-limited public keys. As motivation, note that while Di#e-Hellman key exchange [6] can provide forward security easily in interactive communication, the US Defense Messaging System (DMS) apparently uses transient...