Back to the portfolio

DNS-based certificate revocation service for faster TLS

CybersecurityCommunications & RFComputing, Software & AIConceptPatent pending

This technology routes digital certificate revocation checks through the Domain Name System (DNS) — the same infrastructure browsers already use to look up website addresses. When a browser connects to a website, it needs to confirm the site's security certificate hasn't been revoked; today that check is slow, unreliable, and often skipped. By embedding the revocation check into the DNS lookup that's already happening, the CA's authoritative nameserver can answer 'valid' or 'revoked' in one fast, existing network call. The result is faster, more reliable certificate validation without adding new infrastructure.

What you could build

A DNS-integrated certificate revocation service that certificate authorities or DNS infrastructure providers sell as a drop-in enhancement to their existing certificate issuance and DNS hosting products; buyers would be commercial CAs (DigiCert, Sectigo, Let's Encrypt successors) and enterprise DNS providers.

Who in Virginia should care

Northern Virginia's dense concentration of DNS infrastructure operators, cloud providers (AWS, Azure), and federal cybersecurity contractors (CISA, defense primes) makes this a natural fit for licensing or co-development conversations.

Readiness: Concept

Concept — described but not yet demonstrated. Lab validated — supported by experimental results in the patent. Prototype likely — the text describes a built, working embodiment.

Readiness is inferred from the patent text, not from a lab visit.

The record

Inventors
Taejoong Chung
Filed
Patent pending — filed December 18, 2025
Status
Application
Publication number
US20260180813A1

Ready to talk?

Virginia Tech Intellectual Properties handles licensing for this technology.

VTIP contact coming shortly

Prosim summaries are generated from public patent text and are not legal advice.