Transport Layer Protocols
Transport Layer Protocols
The Transport Layer is responsible for getting data from one application to another across a network — but it doesn't do this in only one way. Different applications have very different needs: a file transfer cannot tolerate a single corrupted byte, while a live video call cannot tolerate waiting for a retransmission. To serve these different needs, several distinct Transport Layer protocols exist, each making a different trade-off between speed, reliability, and overhead.
What Is the Transport Layer, Briefly
The Transport Layer is the fourth layer of the OSI Model. It sits between the Network Layer, which only moves packets between devices, and the applications that actually need to communicate. Its responsibilities include:
- End-to-end communication between applications
- Reliable data delivery (where needed)
- Error detection and recovery
- Flow control
- Segmentation and reassembly
- Multiplexing and demultiplexing
A useful mental model: the Network Layer (IP) is like a courier that delivers a package to the correct building. The Transport Layer is what makes sure it then reaches the correct office inside that building — your web browser, your email client, or your video call application — rather than being dropped in the lobby.
Why the Transport Layer Matters
A modern device typically runs many networked applications at once — browsing, streaming music, downloading a file, and chatting, all simultaneously. The Transport Layer uses port numbers to tell these applications apart and make sure each one receives only the data meant for it.
Port Numbers
A port number is a 16-bit value (allowing numbers from 0 to 65,535) used to identify a specific application or service on a device.
Ports are divided into three ranges:
| Range | Name | Typical Use |
|---|---|---|
| 0 – 1023 | Well-Known Ports | Standard, widely recognized services (HTTP, HTTPS, FTP, DNS, etc.) |
| 1024 – 49151 | Registered Ports | Assigned to specific applications and software vendors |
| 49152 – 65535 | Dynamic / Private Ports | Assigned temporarily, usually by the client side of a connection |
Common well-known ports:
| Service | Port Number |
|---|---|
| HTTP | 80 |
| HTTPS | 443 |
| FTP | 21 |
| SMTP | 25 |
| DNS | 53 |
Major Transport Layer Protocols
The Transport Layer is most commonly associated with two protocols — TCP and UDP — but two other, more specialized protocols, SCTP and DCCP, also exist for specific use cases, along with the newer QUIC protocol that underlies HTTP/3.
User Datagram Protocol (UDP)
What is UDP?
UDP is a simple, lightweight, connectionless protocol. It sends data (called datagrams) without first establishing a connection, and without any guarantee that the data arrives, arrives once, or arrives in order. In exchange for giving up these guarantees, UDP achieves very low overhead and very low latency.
Features of UDP
- Connectionless communication — no handshake before sending data
- Minimal header overhead
- No acknowledgments
- No retransmission of lost packets
- No built-in sequencing
UDP Header
The UDP header is only 8 bytes, consisting of:
- Source Port Number
- Destination Port Number
- Length
- Checksum
Advantages: very fast, low latency, minimal bandwidth consumption, well suited to real-time applications.
Disadvantages: no delivery guarantee, no error recovery, packets may arrive out of order, generally less reliable.
Real-world uses: live video streaming, online gaming, VoIP calls, and DNS queries (where a quick retry is cheaper than the overhead of a full reliable connection).
Transmission Control Protocol (TCP)
What is TCP?
TCP is a connection-oriented protocol that provides reliable, ordered, byte-stream delivery between two endpoints. Before any data is exchanged, TCP first establishes a connection.
How TCP Works
TCP communication proceeds through three phases:
- Connection Establishment — performed via the three-way handshake:
- Client sends
SYN - Server responds with
SYN-ACK - Client responds with
ACK
- Client sends
- Data Transfer — data is exchanged in both directions over the now-established connection.
- Connection Termination — the connection is closed gracefully once communication is complete.
Key Features of TCP
- Reliable delivery — if a segment is lost, TCP detects and retransmits it. This matters, for example, when downloading software: every byte needs to arrive correctly, or the installer could be corrupted.
- Sequence numbers — every byte of data is numbered, which lets TCP detect missing segments, discard duplicates, and reassemble data in the correct order.
- Acknowledgments (ACK) — the receiver confirms what it has received. If the sender doesn't receive an acknowledgment within a timeout, it retransmits the data.
- Flow control — TCP uses a sliding window mechanism, where the receiver advertises how much more data it can currently accept, preventing the sender from overwhelming its buffer.
- Multiplexing — TCP uses port numbers to support many simultaneous application connections.
- Full-duplex communication — data can flow in both directions at the same time; during a video call, for instance, audio and video are sent and received simultaneously.
Applications: web browsing (HTTP/HTTPS), email (SMTP, POP3, IMAP), file transfer (FTP), and online banking — anywhere correctness matters more than raw speed.
Stream Control Transmission Protocol (SCTP)
What is SCTP?
SCTP is a Transport Layer protocol designed to combine some of the strengths of TCP (reliability) with capabilities neither TCP nor UDP offer on their own, such as message-oriented delivery and built-in resilience against network path failures.
Key Features of SCTP
- Message-oriented communication — SCTP transmits distinct messages, rather than treating data as one continuous byte stream the way TCP does. This matches how many applications naturally structure their data.
- Multi-homing — an endpoint can have multiple IP addresses associated with a single SCTP association. If the network path over one address fails, SCTP can fail over to another, which matters for systems (like telecom signaling networks) that need to stay connected through a network fault.
- Multi-streaming — a single SCTP association can carry several independent streams of data. A lost segment in one stream doesn't force all the others to wait for it, avoiding the "head-of-line blocking" that a single TCP connection can suffer from.
- Four-way handshake — SCTP's connection setup uses a cookie-exchange mechanism that helps protect against certain denial-of-service (SYN-flood-style) attacks that affect simpler handshake designs.
Applications: telecommunication signaling (SS7/SIGTRAN), WebRTC data channels, and other systems that need both reliability and resilience to path failures.
Datagram Congestion Control Protocol (DCCP)
What is DCCP?
DCCP is a Transport Layer protocol designed for applications that want congestion control — so they play fairly with other traffic on the network — without paying for the full reliability guarantees of TCP.
Features of DCCP
- Connection-oriented — a connection is established before data is exchanged, similar in spirit to TCP.
- Unreliable delivery — lost packets are not retransmitted; the application decides how to handle loss.
- Congestion control — DCCP actively adjusts its transmission rate to avoid contributing to network congestion, which UDP does not do on its own.
- Feature negotiation — endpoints can negotiate which congestion-control mechanism to use.
Intended uses: multimedia streaming, VoIP, online gaming, and sensor/IoT data — cases that want UDP-like speed but with more network-friendly congestion behavior.
Note: DCCP was standardized to fill this gap between TCP and UDP, but it has seen limited real-world deployment. In practice, many latency-sensitive applications today instead build their own congestion-control logic on top of UDP (as QUIC does) rather than adopting DCCP directly.
Error Control Mechanisms
Reliable protocols such as TCP and SCTP use a consistent set of techniques to detect and recover from transmission problems:
- Checksum — a value calculated over the data, used to detect corruption. If the receiver's recalculated checksum doesn't match, the segment is discarded.
- Acknowledgments — the receiver confirms successful delivery of data it has received.
- Retransmission — segments that are lost or discarded due to corruption are automatically resent.
Flow Control vs. Congestion Control
These two mechanisms are often confused, but they solve different problems:
- Flow control protects the receiver. It prevents a fast sender from overwhelming a slow receiver's buffer. TCP implements this with the sliding window protocol — if a receiver can currently handle only 5 segments, the sender limits itself accordingly.
- Congestion control protects the network. It prevents the combined traffic from all senders from exceeding what the network itself can carry.
What Is Network Congestion?
Congestion occurs when the total traffic on a network path exceeds its available capacity, leading to packet loss, increased delay, and degraded performance for everyone sharing that path.
TCP Congestion Control Techniques
- Slow Start — a new TCP connection begins by sending a small amount of data and increases its sending rate as acknowledgments confirm the network can handle more.
- Congestion Avoidance — once a reasonable sending rate is reached, TCP grows it more cautiously using an Additive Increase, Multiplicative Decrease (AIMD) strategy: increase the rate steadily while things go well, but cut it sharply the moment loss is detected.
- Fast Retransmit — if the sender gets clear evidence a segment was lost (such as repeated duplicate acknowledgments), it retransmits immediately rather than waiting for a timeout.
- Fast Recovery — after a fast retransmit, TCP reduces its sending rate moderately rather than dropping all the way back to slow start, so the connection recovers its throughput more quickly.
A Modern Transport Protocol: QUIC
What is QUIC?
QUIC ("Quick UDP Internet Connections") is a transport protocol originally developed by Google and now standardized by the IETF. Rather than being a new protocol implemented directly in the operating system's networking stack (like TCP and UDP), QUIC is built on top of UDP, which makes it far easier to deploy and update across the existing Internet.
QUIC combines:
- UDP's low connection-setup latency
- TCP-like reliability and congestion control, implemented at the application/transport boundary rather than in the OS kernel
- Encryption (via TLS 1.3) built in by default, rather than layered on separately
Advantages of QUIC
- Faster connection establishment (it can often combine connection setup and encryption negotiation into fewer round trips than TCP + TLS)
- Reduced latency, especially on lossy or high-latency networks
- Independent streams within one connection, avoiding head-of-line blocking between unrelated data
- Built-in encryption by default
- Better performance when a device switches networks (such as moving from Wi-Fi to mobile data)
QUIC and HTTP/3
QUIC is the transport protocol underlying HTTP/3, the current version of the core web protocol. Because QUIC avoids some of the delays inherent in TCP's connection setup and recovery behavior, HTTP/3 can offer faster page loads, smoother video streaming, and fewer stalls on networks with packet loss — particularly on mobile connections.
Choosing the Right Protocol
| Requirement | Best Fit |
|---|---|
| Guaranteed, ordered delivery (file transfer, web pages, email) | TCP |
| Lowest possible latency, loss is tolerable | UDP |
| Message-based delivery with path redundancy (telecom signaling) | SCTP |
| UDP-like speed with network-friendly congestion control | DCCP (rare in practice) or QUIC |
| Modern web traffic needing speed, reliability, and built-in security | QUIC (HTTP/3) |
Related Concepts
- Transport Layer — the broader role these protocols fill; see the dedicated Transport Layer lesson for services like multiplexing and addressing.
- TLS/SSL — the encryption layer traditionally placed on top of TCP, and built directly into QUIC.
- HTTP/3 — the web protocol version built on QUIC.