Hall of FameJ. H. Saltzer, D. P. Reed, D. D. Clark198426 min readpaperintermediate
End-to-End Arguments in System Design
Summary
The paper defines the end‑to‑end argument: functions that can only be correctly implemented with knowledge of the application’s endpoints belong at the endpoints, not in lower layers. Low‑level mechanisms are justified only as performance enhancements, not as substitutes for end‑to‑end checks.
- Place reliability, encryption, and duplicate suppression at the application endpoints when correctness requires end‑to‑end knowledge.
- Low‑level services (e.g., checksum, retransmission) are useful only to improve performance, not to guarantee correctness.
- A reliable data transfer protocol still needs an end‑to‑end checksum and retry logic despite a reliable link layer.
- Implementing functions low in the stack can be uneconomical if failures are rare; end‑to‑end checks handle rare errors efficiently.
System and protocol designers should apply the end‑to‑end principle to avoid unnecessary complexity and cost while ensuring correctness.
9/10
