Skip to main content

TCP (Transmission Control Protocol)

Overview​

TCP is a connection-oriented transport protocol on layer 4 of the OSI model, specified in RFC 9293. It turns the unreliable packet delivery of IP into a reliable, ordered byte stream between two applications: whatever is written on one side arrives on the other side complete, in the correct order and without duplicates, or the connection reports an error. A TCP endpoint is addressed through the combination of IP address and port number.


Characteristics​

PropertyBehaviour in TCP
ConnectionConnection-oriented, a connection is established before the first payload
DeliveryReliable, lost segments are retransmitted
OrderGuaranteed, segments are reordered by sequence number before delivery
DuplicatesDetected and discarded
Data modelContinuous byte stream, message boundaries are not preserved
DirectionFull duplex, both sides may send at the same time
Flow controlYes, via the receive window
Congestion controlYes, the send rate adapts to the load in the network
Header size20 bytes minimum, up to 60 bytes with options
Broadcast / multicastNot possible, a connection always has exactly two endpoints

The overhead of these guarantees consists of a larger header, an additional round trip for connection setup and delay whenever a lost segment has to be retransmitted.


Segment Header​

FieldPurpose
Source portPort of the sending application
Destination portPort of the receiving application
Sequence numberPosition of the first payload byte of this segment in the byte stream
Acknowledgement numberNext byte the sender of this segment expects to receive
FlagsControl bits, see below
WindowNumber of bytes the sender of this segment is currently able to accept
ChecksumError detection over header and payload
OptionsMaximum Segment Size, window scaling, selective acknowledgement

Control Flags​

FlagMeaning
SYN (Synchronize)Requests a connection and synchronises the sequence numbers
ACK (Acknowledgement)The acknowledgement number is valid
FIN (Finish)No more data will be sent in this direction
RST (Reset)Aborts the connection immediately without an orderly teardown
PSH (Push)Asks the receiver to pass the data to the application without delay
URG (Urgent)Marks urgent data (obsolete in practice)

Connection Establishment (Three-Way Handshake)​

Both sides announce their own initial sequence number (x and y in the diagram) and confirm the one of the other side with ack = x + 1 or ack = y + 1.

Client Server

| ---- SYN, seq = x -------------------------> | listening
| |
| <--- SYN, ACK, seq = y, ack = x + 1 -------- | connection accepted
| |
| ---- ACK, ack = y + 1 ---------------------> | connection established
| |
| ==== payload ==============================> |
  • The client knows after the second segment and the server after the third segment that the connection works in both directions.
  • The handshake costs one round trip before the first byte of payload can be sent.
  • A SYN sent to a closed port is answered with RST, which is how a port scan distinguishes a closed port from a filtered one.

Connection Teardown​

An orderly teardown closes each direction separately and therefore takes four segments. FIN only means this side has finished sending. The other direction may still carry data (half-close).

Client Server

| ---- FIN ----------------------------------> |
| <--- ACK ----------------------------------- |
| <--- FIN ----------------------------------- |
| ---- ACK ----------------------------------> |
| |
| (TIME_WAIT, then the connection is released) |

The side that closes first stays in TIME_WAIT for a short period, so that delayed segments of the old connection cannot be mistaken for segments of a new connection on the same port pair. A RST skips this procedure and discards everything still in flight.


Reliability​

  • Sequence numbers: every payload byte has a position in the stream, which allows reordering and duplicate detection.
  • Acknowledgements: the receiver confirms the next expected byte and thereby cumulatively acknowledges everything received so far.
  • Retransmission timeout: a segment that is not acknowledged within the timeout is sent again. The timeout is derived from the measured round trip time.
  • Fast retransmit: several duplicate acknowledgements for the same byte indicate a single lost segment and trigger a retransmission before the timeout expires.
  • Checksum: a corrupted segment is discarded and therefore never acknowledged. The missing acknowledgement triggers a retransmission.
  • Selective acknowledgement (SACK): an option that lets the receiver report exactly which byte ranges arrived, so only the missing ranges are resent.

Flow Control​

Flow control protects the receiver from being overwhelmed. Every segment announces in its window field how many bytes its sender can currently buffer. The other side may never have more unacknowledged data in flight than this window allows.

A receiver whose buffer is full announces a window of zero. The sender then pauses until a later segment announces a larger window.

Congestion Control​

Congestion control protects the network from being overwhelmed and works independently of the receive window. The effective send limit is the smaller of receive window and congestion window.

PhaseBehaviour
Slow startThe congestion window starts small and grows exponentially
Congestion avoidanceAbove a threshold the window only grows linearly
Loss detectedThe window is reduced because packet loss signals congestion
Fast recoveryAfter a fast retransmit the transfer continues with a reduced window

Typical Use Cases​

TCP vs. UDP​

TCPUDP
CriterionCompleteness matters more than latencyA late packet is worthless, or the overhead of a connection exceeds the payload
ExamplesFile transfer, web pages, e-mail, remote administration, database connectionsLive audio and video, online games, simple query/response protocols

Well-Known TCP Ports​

PortService
20/21FTP data / control
22SSH
25SMTP
53DNS zone transfers and responses exceeding the UDP size limit
80HTTP
110/995POP3 / POP3S
143/993IMAP / IMAPS
443HTTPS
3306MySQL / MariaDB

See Also​

  • UDP: the connectionless counterpart without connection setup, reliability or flow control
  • OSI Model: where the transport layer sits between network and session layer