GoodNotes Architect Journal
๐Ÿ  Index 1. Single Server 2. Selecting DB 3. Relational & SQL 4. ACID Integrity 5. NoSQL Types 6. Scaling Guide 7. Load Balancing 8. SPOF & HA 9. API Design 10. Comm Protocols 11. TCP & UDP 12. REST Design 13. GraphQL Architecture 14. Authentication Protocols 15. JWT & OAuth 2 16. Authorization Models
System Design Chapter 11

Transport Layer: TCP & UDP Architecture

Reliability vs. Speed, 3-Way Handshake, Packet Loss Retransmission, and Protocol Selection

โ˜… Core networking layer: understanding trade-offs between guaranteed delivery and ultra-low latency!
โ€œ
In distributed systems, networking is never magic โ€” it is a deliberate engineering negotiation between reliability guarantees and raw speed.
โ€” Transport Layer Architecture Axiom

1 Transport Layer Overview: Reliability vs. Speed

The Transport Layer (Layer 4) serves as the foundational communication bridge between application processes running on different host machines across IP networks. It manages end-to-end data transport, session establishment, packet segmentation, and error recovery.

๐Ÿ›ก๏ธ TCP (Transmission Control Protocol)

Connection-Oriented100% Guaranteed DeliveryIn-Order Stream

Establishes a dedicated full-duplex virtual connection via a 3-Way Handshake. Implements sequence numbering, acknowledgment tracking (ACKs), sliding-window flow control, and automatic retransmission of lost packets.

โš–๏ธ Trade-off: High reliability & integrity at the expense of higher connection setup latency and packet overhead (20โ€“60 byte header).

โšก UDP (User Datagram Protocol)

ConnectionlessZero Handshake LatencyFire-and-Forget

Transmits independent datagram chunks immediately without prior session negotiation. Has no acknowledgment system, no retransmissions, and no packet reordering logic.

โš–๏ธ Trade-off: Blazing-fast 0-RTT speed and ultralight 8-byte header overhead at the expense of potential packet loss and out-of-order delivery.

๐Ÿ“ฆ Packet Header Anatomy & Bandwidth OverheadLayer 4 Frame

๐Ÿ›ก๏ธ TCP Header: 20 โ€“ 60 Bytes

[Src Port: 16b] [Dst Port: 16b]
[Sequence Number: 32b]
[Acknowledgment Number: 32b]
[Flags: SYN, ACK, FIN, RST, PSH, URG]
[Window Size: 16b] [Checksum: 16b] [Optionsโ€ฆ]

โšก UDP Header: 8 Bytes Fixed

[Source Port: 16 bits (2 Bytes)]
[Destination Port: 16 bits (2 Bytes)]
[Total Length: 16 bits (2 Bytes)]
[Checksum: 16 bits (2 Bytes)]
โœจ Thatโ€™s it! 100% pure payload efficiency.

2 TCP (Transmission Control Protocol) Deep-Dive

TCP is engineered for guaranteed reliability. It treats communication as a continuous, reliable byte stream rather than isolated messages.

๐Ÿ”’ The 4 Pillars of TCP Reliability:

1. Delivery Guarantee: Every packet is tracked. Missing packets are automatically resent.

2. Ordered Delivery: Sequence numbers ensure segments are reassembled in exact order.

3. Flow Control: Prevents a fast sender from overwhelming a slow receiver buffer (Sliding Window).

4. Congestion Control: Adjusts sending rates based on network capacity (Slow Start, AIMD).

๐ŸŒŠ Flow Control: Sliding Window

The receiver continuously advertises its available buffer space (Receive Window: rwnd) in every ACK packet. The sender ensures in-flight unacknowledged bytes never exceed this limit, preventing buffer overflow and dropped frames.

๐Ÿšฆ Congestion Control: AIMD

Additive Increase / Multiplicative Decrease: The sender starts with a small Congestion Window (cwnd) during Slow Start, scales linearly while ACKs arrive smoothly, and aggressively cuts the rate in half upon detecting packet loss.

๐Ÿ’ผ Prime Production Use Cases for TCP:

๐Ÿ’ณ Payments & Banking: Stripe, PayPal, SWIFT transfers (zero tolerance for dropped transactions).

๐ŸŒ Web & APIs: HTTPS / REST / GraphQL / gRPC / WebSocket over TLS.

๐Ÿ”‘ Auth & Tokens: OAuth2, JWT verification, session cookie updates.

๐Ÿ“ File & Data Storage: SFTP, FTP, database replication streams (PostgreSQL/MySQL WAL logs).

3 UDP (User Datagram Protocol) Deep-Dive

UDP strips away connection state, flow control, and retransmission logic in exchange for the lowest possible latency and minimal CPU/network overhead.

โšก The 4 Pillars of UDP Architecture:

1. 0-RTT Connectionless: No handshake setup or teardown. First packet carries actual application data.

2. Head-of-Line Free: Dropping packet #3 does not stall packet #4 from reaching the application immediately.

3. Ultralight 8B Overhead: Maximizes useful data payload ratio per Ethernet frame (MTU 1500 bytes).

4. Multicast / Broadcast: Able to stream one packet to thousands of receivers simultaneously.

๐Ÿšซ Eliminating Head-of-Line (HoL) Blocking

In TCP, if segment 3 is lost, segments 4 and 5 must sit buffered in the operating system kernel until segment 3 is retransmitted. UDP passes segments directly to the application layer as soon as they arrive, preserving real-time flow.

๐Ÿ“ก Broadcast & IP Multicast

Because UDP doesnโ€™t maintain two-way connection state machines, a single sender can broadcast datagrams across an entire LAN subnet or multicast stock market quotes to millions of subscribing trading terminals.

๐ŸŽฎ Prime Production Use Cases for UDP:

๐ŸŽฎ Multiplayer Gaming: Player positions & physics state (a stale coordinate resent 200ms late is useless).

๐Ÿ“น Real-Time Audio/Video: WebRTC, Zoom, Discord, Google Meet (prefer brief glitch over audio lag).

๐Ÿ” DNS Lookups (Port 53): Lightweight single-request domain-to-IP resolution queries.

๐Ÿ“Š Metrics & Telemetry: StatsD, Prometheus UDP exporters, syslog log shippers (high throughput).

4 The TCP 3-Way Handshake (SYN โž” SYN-ACK โž” ACK)

Before exchanging application payload data, the client and server must agree on Initial Sequence Numbers (ISNs), verify two-way reachability, and allocate operating system buffer resources.

๐Ÿค Visual TCP 3-Way Handshake & State Machine Ladder
๐Ÿ’ป Client
State: CLOSED

โšก Full-Duplex Negotiation

๐Ÿ–ฅ๏ธ Server
State: LISTEN

Step 1: Client โž” Server

Flags: [SYN=1, ACK=0]

๐Ÿ’ปSYN (Seq = 1000)โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ถ๐Ÿ–ฅ๏ธ

๐Ÿ’ฌ Client Annotation: โ€œHello! I want to open a connection. My Initial Sequence Number (ISN) is 1000.โ€
Client transitions to state: SYN_SENT

Step 2: Server โž” Client

Flags: [SYN=1, ACK=1]

๐Ÿ’ปโ—€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ SYN-ACK (Seq = 5000, Ack = 1001)๐Ÿ–ฅ๏ธ

๐Ÿ’ฌ Server Annotation: โ€œAcknowledged your Seq 1000 (expecting 1001 next). My own ISN is 5000. Letโ€™s sync!โ€
Server transitions to state: SYN_RECEIVED

Step 3: Client โž” Server

Flags: [SYN=0, ACK=1]

๐Ÿ’ปACK (Seq = 1001, Ack = 5001)โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ถ๐Ÿ–ฅ๏ธ

๐Ÿ’ฌ Client Annotation: โ€œGot your Seq 5000! Acknowledged (expecting 5001). Handshake complete โ€” sending payload data now!โ€
Both Client & Server transition to: ESTABLISHED

๐ŸŽ‰ Connection Established! Two-way full-duplex byte streaming channel is live.

๐Ÿ›‘ Bonus Concept: TCP 4-Way Teardown (Connection Termination)

Gracefully closing a TCP connection requires 4 signaling messages because TCP is full-duplex (each half-connection must be closed independently):

  1. Client โž” FIN (I am done sending data)
  2. Server โž” ACK (Got your close request; completing pending writes)
  3. Server โž” FIN (I am also done sending data)
  4. Client โž” ACK (Acknowledged! Enters TIME_WAIT for 2ร—MSL before closing)

5 Packet Delivery & Loss Handling: TCP vs. UDP Side-by-Side

What happens when physical router drops or wireless interference corrupts a packet in transit? Here is the exact side-by-side operational comparison:

๐Ÿ›ก๏ธ TCP: Guaranteed DeliveryZero Loss

Every segment requires an ACK. Loss triggers timeout countdown & retransmission.

๐Ÿ’ป Pkt 1 (Seq 100) โž” In-Flight โž” ๐Ÿ–ฅ๏ธ [ACK 101 โœ“]

๐Ÿ’ป Pkt 2 (Seq 101) โž” In-Flight โž” ๐Ÿ–ฅ๏ธ [ACK 102 โœ“]

๐Ÿ’ป Pkt 3 (Seq 102) โž” Router Drop โŒ โž” [DROPPED!]

โณ RTO Timeout Expired! (No ACK 103 received)

๐Ÿ’ป Resend Pkt 3 โž” Retransmitted โž” ๐Ÿ–ฅ๏ธ [ACK 103 โœ“]

๐Ÿ’ป Pkt 4 (Seq 103) โž” In-Flight โž” ๐Ÿ–ฅ๏ธ [ACK 104 โœ“]

๐Ÿ›ก๏ธ Delivery Guarantee Outcome:

  • 100% Data Integrity: No gaps, zero lost bytes.
  • Sequence Preservation: Application receives clean ordered stream.
  • Latency Cost: Retransmission causes a momentary latency stall (jitter).
โšก UDP: Fire-and-ForgetZero Latency

Packets are blasted immediately. Lost packets are discarded without waiting.

๐Ÿ’ป Frame 1 โž” 0-RTT Blast โž” ๐Ÿ–ฅ๏ธ [Received โœ“]

๐Ÿ’ป Frame 2 โž” 0-RTT Blast โž” ๐Ÿ–ฅ๏ธ [Received โœ“]

๐Ÿ’ป Frame 3 โž” Router Drop โŒ โž” [DROPPED!]

โฉ No Retransmission โ€” Stream Marches Forward Instantly

๐Ÿ’ป Frame 4 โž” 0-RTT Blast โž” ๐Ÿ–ฅ๏ธ [Received โœ“]

๐Ÿ’ป Frame 5 โž” 0-RTT Blast โž” ๐Ÿ–ฅ๏ธ [Received โœ“]

โšก Speed Maximization Outcome:

  • Ultra-Low Jitter: Zero delay spike waiting for dropped segments.
  • Application Tolerant: Video codec masks missing frame (pixel interpolation).
  • Ideal for Real-Time: Live stream continues smoothly without buffering.

6 Architectural Comparison Matrix & Decision Guide

Feature / Metric๐Ÿ›ก๏ธ TCP (Transmission Control)โšก UDP (User Datagram)
Connection ModelConnection-Oriented (3-Way Handshake)Connectionless (0-RTT, Fire-and-forget)
Delivery Guarantee100% Guaranteed (ACK tracking + Retries)Best Effort (No ACKs, packets may drop)
Packet OrderingStrictly In-Order (Sequence numbered)No Order Guarantee (Out-of-order arrival)
Header Overhead20 โ€“ 60 Bytes (Heavy metadata flags)8 Bytes Fixed (Minimal lightweight header)
Speed & LatencyModerate latency (Handshake + ACKs + Head-of-Line wait)Blazing fast, minimal latency & jitter
Flow & Congestion ControlYes (Sliding Window, AIMD, Slow Start)No (Application must implement if needed)
Broadcast / MulticastNo (Strictly Point-to-Point Unicast)Yes (Unicast, Multicast, Broadcast)
Typical Protocol StackHTTP/1.1, HTTP/2, WebSockets, TLS, gRPC, SSH, SFTPDNS, WebRTC, VoIP (SIP/RTP), QUIC (HTTP/3), DHCP, NTP
๐Ÿš€ Modern System Design Trend: QUIC & HTTP/3

Why choose between TCP and UDP when you can have both? The latest web standard โ€” HTTP/3 (QUIC) โ€” runs on top of UDP in the kernel, but implements encryption (TLS 1.3), stream multiplexing, and reliability in user space. This eliminates TCPโ€™s Head-of-Line blocking while keeping 100% guaranteed delivery!