KS3 & GCSE Computing · GCSE

The TCP Three-Way Handshake Explained for GCSE Computer Science

Discover how the TCP three-way handshake establishes a reliable connection for GCSE Computer Science: SYN, SYN-ACK, and ACK packets explained step by step.

Duke Harewood — author of AI Tutors for Key Stage 3Updated 5 min read

On this page

Short answer

Before two computers exchange data over TCP, they perform a three-way handshake to confirm both ends are ready and to synchronise sequence numbers. This handshake uses three packets — SYN, SYN-ACK, and ACK — and occurs in milliseconds before any application data is sent.

At a glance

Key stage
GCSE
Subject
Computing
Type
Guide
For
Students
Read time
5 min
Last updated
8 October 2026

Where this fits

  1. Key Stage 3Years 7–9
  2. GCSEYears 10–11This article
This article is aimed at GCSE (Years 10–11), the stage after Key Stage 3 (Years 7–9).

Method at a glance

  1. The sender numbers every byte it transmits
  2. The receiver sends ACKs confirming receipt
  3. If an ACK does not arrive within a timeout period, the sender…
The 3 numbered steps in this article, in order.

Why does TCP need a handshake at all?

TCP (Transmission Control Protocol) guarantees reliable, ordered delivery of data. To achieve this, both the client and the server must:

  • Confirm the other end is alive and reachable.
  • Agree on the starting sequence numbers — counters that track which bytes have been sent and received, allowing lost packets to be detected and retransmitted.
  • Allocate buffer space for incoming data.

Without this setup, a server might send data to a client that is no longer listening, or the client might receive packets out of order with no way to reassemble them correctly.

What happens in each of the three steps?

The handshake is initiated by the client (the device requesting the connection) and responded to by the server (the device accepting it).

Step Direction Packet Key flag What it means
1 Client → Server SYN SYN = 1 "I want to connect; my starting sequence number is X."
2 Server → Client SYN-ACK SYN = 1, ACK = 1 "I'm ready; my sequence number is Y; I acknowledge your X."
3 Client → Server ACK ACK = 1 "I acknowledge your Y; connection established."

After step 3, the connection is established and application data (an HTTP request, an email, a file transfer) can begin flowing.

What are SYN, ACK, and sequence numbers?

SYN stands for synchronise. It signals the desire to begin a connection and carries an Initial Sequence Number (ISN) — a randomly chosen starting value (not always 0, to prevent security attacks). The random start makes it harder for an attacker to forge packets by guessing sequence numbers.

ACK stands for acknowledge. Every packet after the first SYN includes an acknowledgement number equal to the other side's sequence number plus one, meaning "I have received everything up to byte n; please send byte n+1 next."

Think of it like starting a phone call. You say "Hello, can you hear me?" (SYN). The other person replies "Yes, I can hear you — can you hear me?" (SYN-ACK). You say "Yes!" (ACK). Only then does the actual conversation begin.

How does the handshake relate to TCP's reliable delivery?

The sequence and acknowledgement numbers established during the handshake are used throughout the connection:

  1. The sender numbers every byte it transmits.
  2. The receiver sends ACKs confirming receipt.
  3. If an ACK does not arrive within a timeout period, the sender retransmits the unacknowledged data.

This process is called ARQ (Automatic Repeat reQuest). The handshake sets up the counters that make ARQ possible.

What is the difference between TCP and UDP in terms of connection setup?

Feature TCP UDP
Connection setup Three-way handshake required No setup — connectionless
Reliability Guaranteed delivery and ordering No guarantee; packets may be lost or reordered
Speed Slower (overhead from handshake and ACKs) Faster (no overhead)
Use cases Web browsing, email, file transfer Video streaming, online gaming, DNS queries

UDP sends packets immediately without checking whether the recipient is ready. This makes it faster but unreliable. For a live video call, a dropped frame is acceptable; for a bank transfer, it is not — hence TCP.

What is a SYN flood attack?

A SYN flood is a denial-of-service attack that exploits the handshake. An attacker sends thousands of SYN packets with spoofed source addresses. The server sends SYN-ACK responses and allocates memory waiting for ACKs that never arrive. Eventually, the server's connection table fills up and it can no longer accept legitimate connections.

Modern defences include SYN cookies — a technique where the server does not allocate memory until the final ACK arrives, making a SYN flood much less effective.

Frequently asked questions

Do I need to remember the sequence numbers for my GCSE exam?

You do not need to recall specific sequence number values. You need to understand that sequence numbers exist, that they are exchanged during the handshake, and that they enable TCP's reliability guarantees. Being able to describe the three steps (SYN, SYN-ACK, ACK) and explain why each is necessary is the key exam skill.

Why is it called a "three-way" handshake rather than a two-way?

Two packets (SYN and SYN-ACK) would confirm the server can hear the client, but the client's ACK confirms the server can be heard too. Without step 3, the server does not know its SYN-ACK got through. Both sides need to prove their transmissions are reaching the other; that requires three messages.

What happens if one of the handshake packets is lost?

TCP uses retransmission timers. If the client sends a SYN and receives no SYN-ACK within a set time, it retransmits the SYN. Similarly, if the server never receives the final ACK, it eventually gives up and the connection attempt fails. The client will typically retry several times before reporting a connection error to the application.

Is the handshake encrypted in HTTPS?

In HTTPS, the TCP three-way handshake completes first (in plaintext). Immediately afterwards, a TLS handshake takes place to negotiate encryption keys. Once TLS is set up, all application data — including the HTTP request and response — travels inside an encrypted channel. The TCP handshake itself is never encrypted because it must be handled by networking hardware before the application layer is involved.


Want to trace through a TCP handshake diagram and test your understanding? Professor Turing at aitutors.me can quiz you on every packet and flag.

Key terms

  • sequence numbers
  • client
  • server
  • established
  • SYN
  • Initial Sequence Number (ISN)
  • ACK
  • ARQ (Automatic Repeat reQuest)

Sources