Part 5 · 2 chapters · ~12 min
UDP and QUIC
UDP's minimal promises and where they fit, QUIC as reliable encrypted transport over UDP, faster handshakes and 0-RTT with replay caveats, independent streams and head-of-line blocking, connection migration, user-space congestion control, and operational differences (UDP blocking, load balancing by connection ID).
10
Transport rebuilt
QUIC lives in user space (in the browser, in the server library), so it can evolve without waiting for operating system kernels. That is why it shipped quickly, and why it costs more CPU per byte than kernel TCP today.
UDP AND QUIC
reliability rebuilt in user space over UDP, with encryption built in
swipe the figure sideways, or tap expand for full screen
1/5
UDP
UDP sends datagrams with ports and a checksum: no handshake, no ordering, no retransmission, no congestion control. Ideal for DNS queries, games, voice and video, and as a base for new protocols.
datagrams, nothing moreDNS, real-time media, new protocols
11
Operating QUIC
| topic | what to know |
|---|---|
| 0-RTT | resumed connections can send data in the first packet, but that data can be replayed by an attacker: only allow idempotent requests in 0-RTT |
| UDP blocked | some corporate networks block UDP 443; browsers fall back to TCP (HTTP/2) automatically |
| load balancing | balance by QUIC connection ID, not the 5-tuple, or migrating clients hit a different server |
| CPU cost | user-space crypto and packet handling cost more CPU than kernel TCP with offloads |
| where it runs | usually at the CDN or edge proxy; origins often still speak HTTP/1.1 or HTTP/2 |