Sorry, this is not indicated. He was supposed to be the only one for this jvm at this point in time. That is, session identifiers can be reused several times a day while no one else has a session. I agree that most actual implementations can provide a more reliable guarantee, but I don't think you can count on that.
Take a look at this mailing list - in it people discuss reusing session identifiers in both tomcat and tar.
So, basically the assumption that the session identifier is unique, is valid only until the session is destroyed.
source share