NVIDIA calls this architecture scale-in networking. The 7.2 Tb/s figure does not represent BlueField-4's raw bandwidth. NVIDIA says the DPU itself delivers 2× the network bandwidth of BlueField-3. The 18× figure — 7.2 Tb/s versus 400 Gb/s — refers to traffic under security and orchestration control.
BlueField-3 vs. BlueField-4
| BlueField-3 | BlueField-4 | |
| Secured traffic scope | 400 Gb/s access link | Up to 7.2 Tb/s across orchestrated NICs |
| Managed traffic | — | increase18× |
| DPU network bandwidth | Baseline | 2× |
| NIC control | Primarily local interface | Multiple ConnectX-9 interfaces |
| Security scope | GPU server | AI-factory infrastructure |
| Storage | External/front-end network | Integrated into managed fabric |
| Platform | Hopper / Blackwell | Vera Rubin |
The main upgrade is therefore not bandwidth but control scope.
BlueField-4 + ASTRA
The key component is Advanced Secure Trusted Resource Architecture (ASTRA), NVIDIA's out-of-band management and policy-enforcement architecture.
ASTRA allows BlueField-4 to orchestrate other NICs instead of applying security only to traffic crossing the DPU's own interface.
The stack consists of:
- BlueField-4 — DPU and infrastructure controller;
- ASTRA — policy enforcement and isolation;
- ConnectX-9 — network interfaces controlled by the architecture;
- Spectrum-X — Ethernet fabric;
- DOCA — DPU software stack.
NVIDIA networking chief Gilad Shainer described the change:
We provide the technology to connect to everything.
BlueField-4 can consequently enforce security domains across traffic carried by multiple NICs without requiring that entire 7.2 Tb/s data stream to pass through the DPU itself.
400 Gb/s vs. 7.2 Tb/s
BlueField-3 secured its own 400 Gb/s access connection.
BlueField-4 can manage security across interfaces carrying up to 7.2 Tb/s:
7.2 Tb/s ÷ 400 Gb/s = 18×
This needs to be separated from physical DPU throughput:
| Metric | BlueField-4 improvement |
| DPU network bandwidth | 2× BlueField-3 |
| Traffic under security/orchestration | 18× |
| Storage throughput | Up to 1.45× off-the-shelf Ethernet |
The 18× number measures managed network reach, not an 18× faster DPU.
Storage: Up to 1.45× Throughput
NVIDIA claims scale-in can deliver up to 1.45× higher storage throughput than off-the-shelf Ethernet. Two components are involved. BlueField-4 offloads data movement from the host CPU, reducing CPU overhead. Spectrum-X Ethernet handles the storage fabric and uses NVIDIA's congestion-management mechanisms to improve utilization.
Storage therefore becomes part of the managed AI network rather than a separate front-end service.
A simplified path is:
- Storage → Spectrum-X → ConnectX-9 → GPU/CPU infrastructure
- with BlueField-4 + ASTRA providing orchestration and security.
Security Expands Beyond One Server
BlueField-3 primarily protected the network boundary around its GPU server.
With BlueField-4 and ASTRA, NVIDIA plans to extend policy enforcement across:
- ConnectX-9 NICs;
- storage infrastructure;
- CPU racks;
- GPU compute;
- models;
- tenant isolation;
- confidential-computing environments.
This is designed for AI infrastructure where multiple users and workloads share compute, networking and storage resources.
Why NVIDIA Calls It Scale-In
NVIDIA now describes five networking domains:
| Domain | Scope |
| Scale-up | Connectivity inside tightly coupled GPU systems |
| Scale-out | GPU/compute connectivity across racks |
| Scale-across | Connectivity across campuses or facilities |
| Context-scale / CMX | Context storage outside individual GPU servers |
| Scale-in | Bringing CPUs, storage, models and security into the managed AI fabric |
Scale-in differs from scale-up and scale-out because it isn't primarily aimed at increasing GPU-to-GPU bandwidth. It integrates the infrastructure surrounding GPU compute.
Blackwell vs. Vera Rubin
The architecture changes from:
- Blackwell / BlueField-3
- GPU server → BlueField-3 → 400 Gb/s access network
to:
- Vera Rubin / BlueField-4
- BlueField-4 + ASTRA → ConnectX-9 → Spectrum-X → GPUs + CPUs + storage
The traditional split between a GPU back-end network and a generic front-end network becomes less distinct.
As Shainer put it:
The front-end is no more front-end.
What Changes
BlueField-4 introduces three relevant changes over BlueField-3:
2× DPU network bandwidth.
Up to 7.2 Tb/s of traffic under security and orchestration control versus a 400 Gb/s BlueField-3 access link. Up to 1.45× storage throughput compared with off-the-shelf Ethernet, according to NVIDIA.
The architectural change is larger than the raw bandwidth increase. BlueField-4 moves from securing primarily its own server connection to orchestrating NICs and enforcing policies across compute, storage and networking infrastructure. That's the technical basis for NVIDIA's new scale-in networking layer.
Marina Lyubimova
Marina Lyubimova