A KDC could store a handle into a database, a KDC could accept the possibility of replays, a KDC could store state associated with a session with an OTP server. Forc this protocol accepting replays is probably a bad idea.