Part 5 · 2 chapters · ~12 min

UDP and QUIC

UDP's minimal promises and where they fit, QUIC as reliable encrypted transport over UDP, faster handshakes and 0-RTT with replay caveats, independent streams and head-of-line blocking, connection migration, user-space congestion control, and operational differences (UDP blocking, load balancing by connection ID).

10

Transport rebuilt

QUIC lives in user space (in the browser, in the server library), so it can evolve without waiting for operating system kernels. That is why it shipped quickly, and why it costs more CPU per byte than kernel TCP today.

UDP AND QUIC
reliability rebuilt in user space over UDP, with encryption built in
UDPports + checksum onlyQUICstreams, reliability, TLS 1.3 insideTCP head-of-lineone loss stalls all streamsQUIC streamsone loss stalls one streamconnection IDssurvive Wi-Fi → 4G
swipe the figure sideways, or tap expand for full screen
1/5
UDP
UDP sends datagrams with ports and a checksum: no handshake, no ordering, no retransmission, no congestion control. Ideal for DNS queries, games, voice and video, and as a base for new protocols.
datagrams, nothing moreDNS, real-time media, new protocols
11

Operating QUIC

topicwhat to know
0-RTTresumed connections can send data in the first packet, but that data can be replayed by an attacker: only allow idempotent requests in 0-RTT
UDP blockedsome corporate networks block UDP 443; browsers fall back to TCP (HTTP/2) automatically
load balancingbalance by QUIC connection ID, not the 5-tuple, or migrating clients hit a different server
CPU costuser-space crypto and packet handling cost more CPU than kernel TCP with offloads
where it runsusually at the CDN or edge proxy; origins often still speak HTTP/1.1 or HTTP/2