PrepZone Logo
PrepZone

Network Protocols

TCP, UDP, HTTP and TLS — the transport stack every distributed system sits on.

Read these first

The protocol stack

Layers bottom to top

  • IP (Layer 3) — addresses and routes packets between hosts; no delivery guarantee.
  • TCP / UDP (Layer 4) — transport: reliability vs speed.
  • TLS (Layer 4–5) — encryption and identity on top of TCP.
  • HTTP/1.1, HTTP/2, HTTP/3 (Layer 7) — request/response semantics for APIs and web.
  • WebSocket — full-duplex channel over HTTP upgrade (covered in a later article).
Java
Application  │  HTTP GET /api/v1/feed
TLS          │  encrypted record
TCP          │  segment, port 443
IP           │  packet, src → dst

Network stack (StreamHub request)

NETWORKL7 HTTP/2 + RESTAPI Gateway / ALB
NETWORKL4 TCPALB → EKS targets
NETWORKL3 IP + VPCsubnets · security groups
NETWORKDNSRoute 53 resolves hostname
Where HTTP/2, TLS, TCP, and DNS each sit in a cloud API call.

TCP vs UDP

AspectTCPUDP
DeliveryGuaranteed, orderedBest effort, no order guarantee
Connection3-way handshake, statefulConnectionless
OverheadHigher (retransmits, flow control)Lower latency
Use casesHTTP, APIs, databasesDNS, video streaming, gaming, VoIP
  • Delivery

    TCPGuaranteed, ordered
    UDPBest effort, no order guarantee
  • Connection

    TCP3-way handshake, stateful
    UDPConnectionless
  • Overhead

    TCPHigher (retransmits, flow control)
    UDPLower latency
  • Use cases

    TCPHTTP, APIs, databases
    UDPDNS, video streaming, gaming, VoIP

Default to TCP for APIs; choose UDP when loss is acceptable and latency dominates.

StreamHub uses TCP for all API traffic and metadata. Live low-latency preview streams experiment with UDP-based protocols (WebRTC) where occasional frame loss is acceptable.

HTTP versions

VersionKey traitImpact
HTTP/1.1One request per connection (without pipelining)Many connections needed; head-of-line blocking
HTTP/2Multiplexed streams on one TCP connectionFewer connections; better for asset-heavy pages
HTTP/3QUIC over UDPFaster handshake, no TCP head-of-line blocking
  • HTTP/1.1

    Key traitOne request per connection (without pipelining)
    ImpactMany connections needed; head-of-line blocking
  • HTTP/2

    Key traitMultiplexed streams on one TCP connection
    ImpactFewer connections; better for asset-heavy pages
  • HTTP/3

    Key traitQUIC over UDP
    ImpactFaster handshake, no TCP head-of-line blocking
Java
GET /api/v1/videos/v_9182 HTTP/2
Host: api.streamhub.com
Accept: application/json
Authorization: Bearer eyJhbG...

HTTP/2 200
content-type: application/json
cache-control: max-age=60

{"id":"v_9182","title":"Sunset timelapse","duration_sec":142}

TLS essentials

TLS provides confidentiality, integrity, and server authentication via certificates.

TLS in system design

  • HTTPS everywhere — terminate TLS at LB or reverse proxy; internal mesh may use mTLS.
  • Handshake cost — 1–2 RTT; mitigate with HTTP/2 connection reuse and TLS session resumption.
  • Certificate management — Let's Encrypt, ACM; automate renewal.
  • TLS 1.2+ — disable legacy ciphers in production.
Java
# Inspect certificate chain
openssl s_client -connect api.streamhub.com:443 -servername api.streamhub.com </dev/null 2>/dev/null | openssl x509 -noout -dates -subject

Connection lifecycle and latency

Each new TCP + TLS connection costs round trips. At scale:

  • Keep-alive — reuse connections from client pools.
  • Connection pooling — app → database pools (PgBouncer, HikariCP).
  • Edge termination — CDN/LB handles TLS close to users.
Java
# NGINX keepalive toward upstream app servers
upstream streamhub_api {
  server app-1:8080;
  server app-2:8080;
  keepalive 32;
}

Three round trips (TCP + TLS) before the first byte of HTTP can dominate p99 for small API responses.

Ports and firewalls

PortProtocolTypical use
80HTTPRedirect to 443 or internal only
443HTTPSPublic APIs and web
5432TCPPostgres (internal VPC only)
6379TCPRedis (internal, AUTH required)
  • 80

    ProtocolHTTP
    Typical useRedirect to 443 or internal only
  • 443

    ProtocolHTTPS
    Typical usePublic APIs and web
  • 5432

    ProtocolTCP
    Typical usePostgres (internal VPC only)
  • 6379

    ProtocolTCP
    Typical useRedis (internal, AUTH required)

Security groups and network ACLs restrict which ports are reachable from the internet vs internal subnets only.

Protocol choice for APIs

For REST/JSON APIs over the public internet: HTTPS on TCP (HTTP/2 or HTTP/3). gRPC uses HTTP/2 with protobuf — better for internal service mesh, less browser-friendly.

Quick recall

Everything you need if you only revisit this box.

  • IP routes packets; TCP delivers reliably; UDP is faster but lossy.
  • HTTP/2 multiplexes streams; HTTP/3 uses QUIC over UDP.
  • TLS adds encryption and handshake cost — reuse connections and terminate at the edge.
  • Connection pooling reduces per-request setup overhead for APIs and databases.
  • Default public APIs to HTTPS; restrict database ports to internal networks.
  • Protocol choice follows latency, reliability, and client constraints.

Test yourself

Answer these before moving on — recall is what makes it stick.