# NVIDIA DOCA

> Source: https://aiwiki.ai/wiki/nvidia_doca
> Updated: 2026-09-28
> Fact-checked: 2026-09-28
> Categories: AI Infrastructure, Developer Tools, NVIDIA
> License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/) - attribute to "AI Wiki (aiwiki.ai)"
> Cite as: AI Wiki. "NVIDIA DOCA." aiwiki.ai, 28 Sept 2026. https://aiwiki.ai/wiki/nvidia_doca
> From AI Wiki (https://aiwiki.ai), the free encyclopedia of artificial intelligence. Reuse freely with attribution.

**NVIDIA DOCA** is [Nvidia](https://aiwiki.ai/wiki/nvidia)'s software framework for programming its [BlueField](https://aiwiki.ai/wiki/bluefield) data processing units (DPUs) and SuperNICs and its [ConnectX](https://aiwiki.ai/wiki/connectx) network adapters. It combines a software development kit (SDK) of libraries, drivers, tools and reference applications with a runtime that ships on every BlueField device, plus a host-side package (DOCA-Host) that has replaced Nvidia's older MLNX_OFED driver stack for newer adapters. NVIDIA announced DOCA together with BlueField-2 at its GPU Technology Conference on October 5, 2020, describing it as a "data-center-infrastructure-on-a-chip architecture" and pitching the SDK as the DPU counterpart of [CUDA](https://aiwiki.ai/wiki/cuda): NVIDIA compared building DPU-accelerated infrastructure applications with DOCA to building GPU-accelerated applications with the CUDA programming model. [2][3] As of September 2026 the current release is DOCA 3.5.0, published in July 2026, with an LTS release (3.6) scheduled for October 2026 and DOCA 4.0 for January 2027. [8][9][10]

DOCA started as a way to offload networking, storage and security work from host CPUs. Since 2025 NVIDIA has positioned it primarily as security and infrastructure software for AI data centers: the DOCA Argus runtime threat detection service (April 2025), DOCA microservices for BlueField-4 (October 2025), a DOCA security stack for the Vera BlueField-4 STX storage platform (May 2026), and, on September 28, 2026, NVIDIA Sentry, the out-of-band agent watchdog in the [NVIDIA Open Agent Safety Platform](https://aiwiki.ai/wiki/nvidia_open_agent_safety_platform), which NVIDIA says "is built on NVIDIA DOCA software." [21][23][25][28]

## Overview

NVIDIA's developer page describes DOCA as software that "consists of an SDK and a runtime environment." The runtime, included by default with BlueField, has tools for "provisioning, deploying, and orchestrating containerized services on hundreds or thousands of DPUs and SuperNICs across the data center," while the SDK provides "industry-standard open APIs and software frameworks," drivers, libraries, tools, documentation and example applications. [1] The DOCA documentation groups the software into two installation packages: [7]

| Package | Installed on | Contents |
|---|---|---|
| DOCA-Host | The host server | Drivers and tools for BlueField and ConnectX devices, offered as installation profiles (doca-all, doca-networking, doca-ofed, doca-roce, doca-host-basic) |
| BlueField-Bundle (BF-Bundle) | BlueField Arm cores (preinstalled) | DOCA SDK libraries, drivers and tools; BlueField platform software (bootloaders, firmware); Ubuntu 22.04 as the default operating system for the Arm cores |
| BlueField-Firmware Bundle (BF-FWBundle) | BlueField Arm cores | A minimal package with ATF, UEFI, NIC firmware, BMC firmware and eROT firmware, but no DOCA SDK and no operating system |

On a host or on the BlueField itself, DOCA components are installed under `/opt/mellanox/doca`, a path that reflects the BlueField line's origins at [Mellanox](https://aiwiki.ai/wiki/mellanox). [27] The DOCA license agreement is still issued in the name of "Mellanox Technologies, Ltd." [18]

The DOCA 3.5.0 release notes state that BlueField-3 devices "must use DOCA-Host as the host driver" and are not supported by MLNX_OFED, and that BlueField-2 and ConnectX-7 are the last generations supported by MLNX_OFED. [8][11][50] For hosts, NVIDIA recommends the doca-all profile for BlueField devices and doca-networking for ConnectX adapters; doca-ofed installs only the MLNX_OFED-equivalent drivers. [12]

NVIDIA's documentation divides DOCA software into three layers. DOCA microservices are "production-ready, containerized infrastructure services" such as DOCA Argus and DOCA SNAP that can be pulled from the NVIDIA NGC catalog; DOCA libraries are programmable APIs for BlueField hardware capabilities such as packet processing, congestion control and GPU networking; and DOCA drivers provide the underlying networking, security and storage interfaces. [2] BlueField devices can run in DPU mode, zero-trust mode or NIC mode, and DOCA documents each. [6]

## History

| Date | Milestone |
|---|---|
| October 5, 2020 | NVIDIA announces BlueField-2 DPUs and the DOCA SDK at GTC. Canonical announces Ubuntu support for BlueField-2 and DOCA; VMware, Red Hat and Check Point describe work or plans to support BlueField-2. [3] |
| April 12, 2021 | DOCA 1.0 described: BlueField-2 is generally available and DOCA is in early availability, with reference applications for a load balancer and a firewall agent built on DOCA Flow and DPI libraries. [4] |
| October 2022 | DOCA 1.5.0 LTS released. [10] |
| March 21, 2023 | At GTC 2023, NVIDIA announces DOCA general availability, "which opens access to everyone," saying more than 4,700 early-access developers were already using it. DOCA 2.0 adds BlueField-3 support including the data path accelerator (DPA), an IPsec library, device attestation and YARA rules; the same post introduced the GPUNetIO library, then in early access. [5] |
| October 2023 | DOCA 2.5.0 LTS released. [10] |
| October 2024 | DOCA 2.9.0 released; the 2.9.x branch becomes the LTS24 line. [10] |
| April 2025 | DOCA 3.0.0 released. [10] |
| April 28, 2025 | NVIDIA introduces DOCA Argus, an agentless runtime threat detection framework running on BlueField. [21][22] |
| June 25, 2025 | NVIDIA describes DOCA 3.0 features, including DOCA Platform Framework general availability for trusted hosts and support for ConnectX-8 SuperNICs with Quantum-X800 InfiniBand. [20] |
| October 2025 | DOCA 3.2.0 released as the LTS25 line. [10] |
| October 28, 2025 | NVIDIA announces BlueField-4 with "native support for NVIDIA DOCA microservices." [23] |
| May 31, 2026 | At GTC Taipei, NVIDIA announces DOCA Vault microservices and enhanced DOCA Argus and DOCA Flow capabilities for Vera BlueField-4 STX. [25] |
| July 2026 | DOCA 3.5.0 released. [10] |
| September 28, 2026 | NVIDIA Sentry, part of the NVIDIA Open Agent Safety Platform reference design, is described as built on DOCA. [28][29] |
| October 2026 (planned) | DOCA 3.6.0, an LTS release, scheduled. [8] |
| January 2027 (planned) | DOCA 4.0 scheduled. [8][9] |

The 2020 announcement framed DOCA as a comprehensive, open platform for "software-defined, hardware-accelerated networking, storage, security and management applications running on the BlueField family of DPUs," and said DOCA was fully integrated into NVIDIA NGC, NVIDIA's container software catalog. [3] The April 2021 DOCA 1.0 description, by John Kim and Ariel Kit, listed several capabilities still missing from the SDK at the time, including DOCA-level libraries for IPsec, time synchronization and provisioning, which NVIDIA said would come in later releases. [4]

## Libraries

The DOCA SDK is built on DOCA Core, which provides a device abstraction for discovering, querying and opening the hardware acceleration units in BlueField and ConnectX devices; the other libraries sit on top of it and "can be combined into processing pipelines or workflows." [13] NVIDIA's DOCA 3.0 announcement cited "over 20 specialized libraries." [20] The table lists a selection of libraries documented in DOCA 3.5.0.

| Library | Purpose (per NVIDIA documentation) |
|---|---|
| DOCA Flow | "The most fundamental API for building generic packet processing pipes in hardware": chains of pipes, each with match criteria, monitoring and actions, running on the host or on BlueField [14] |
| DOCA GPUNetIO | Lets CUDA kernels send and receive network packets directly, removing the CPU from the critical path by combining GPUDirect RDMA, GPUDirect Async Kernel-Initiated (GDAKI) networking, GDRCopy and the BlueField DMA engine [15] |
| DOCA DPA | Programming model for the BlueField-3 data path accelerator, an embedded multi-threaded processor programmed in C for packet and I/O processing [16] |
| DOCA DMA, Comch, RDMA, Ethernet | Direct memory access, a communication channel between host applications and servers on the BlueField Arm cores, RDMA, and Ethernet packet queues [6] |
| DOCA App Shield | Reads host or virtual machine memory from the DPU over DMA for intrusion detection and forensics [17] |
| DOCA Compress, SHA, AES-GCM, Erasure Coding | Hardware-accelerated compression, hashing, encryption and erasure coding [6][20] |
| DOCA Rivermax | DOCA API for NVIDIA Rivermax media and data streaming; requires a Rivermax license [51] |
| DOCA UROM | Unified Resource and Offload Manager for offloading parts of HPC and AI parallel computing tasks from the host to DPU workers [52] |
| DOCA STA | Offloads storage target applications such as SPDK to the BlueField-3 DPA [53] |
| DOCA Device Emulation | Emulates PCIe devices, including virtio-net, virtio-blk and virtio-fs, toward the host [54] |
| DOCA Telemetry and Telemetry Exporter | Device counters (PCI, PHY, congestion control, DPA) and export of application telemetry [55] |

DOCA GPUNetIO shows how DOCA ties the network adapter to the GPU. In NVIDIA's 2023 example, the Aerial 5G software used GPUNetIO to let a CUDA kernel per radio cell receive packets directly, and NVIDIA reported that system capacity rose from four cells with a CPU-centric design to 16 cells. [5] NVIDIA's DOCA 3.0 post said the GPUNetIO and RDMA libraries support deployments "beyond 100K GPUs"; that is NVIDIA's claim. [20]

## Services

DOCA services are containerized DOCA-based programs for a given use case, published on NGC with "DOCA" and "DPU" labels and deployable to BlueField and in some cases to the host. [19][27]

| Service | Function |
|---|---|
| DOCA Platform Framework (DPF) | Provisions BlueField DPUs and orchestrates DPU services at fleet scale through Kubernetes APIs and custom resources; supports "Host Trusted" and "Zero Trust" deployment models [19][30] |
| DOCA Argus | Agentless runtime threat detection from BlueField's isolated trust domain (see below) [19][31] |
| DOCA Host-Based Networking (HBN) | Runs BGP/EVPN routing on BlueField; its nl2docad daemon mirrors Linux routing and bridging tables into BlueField hardware tables [19][32] |
| OVS-DOCA | Open vSwitch accelerated with DOCA libraries and NVIDIA ASAP2 [6] |
| DOCA SNAP | Presents networked storage to the host as local NVMe, virtio-blk or virtio-fs devices by emulating drives on the PCIe bus [33] |
| DOCA Telemetry Service (DTS) | Real-time system and workload metrics, built into the BlueField image and available on NGC for hosts [34] |
| DOCA Firefly | Precision Time Protocol (PTP) time synchronization for BlueField [35] |
| DOCA Management Service (DMS) | One CLI (dms-cli) and YANG-model interface for configuring BlueField and ConnectX devices, replacing separate tools such as mlxconfig and devlink [36] |
| DOCA Pipeline Language (DPL) | A packet-processing language derived from P4-16, with a compiler, runtime service and debugging tools, controlled at runtime through P4Runtime [37] |
| DOCA XPlane | Manages plane failover in OVS-DOCA for multi-plane ConnectX-8 SuperNICs on a Spectrum-X fabric [56] |
| DOCA BlueMan, Flow Inspector, UROM, Virtio-net | Web dashboard for BlueField inventory and telemetry, mirrored-traffic analysis, UROM workers, and virtio-net emulation [19] |

NVIDIA's documentation notes that "while DPL's syntax is derived from P4-16, its pipeline semantics align with NVIDIA's DPU architecture rather than standard P4 execution models": BlueField uses a run-to-completion disaggregated RMT (dRMT) model rather than P4's staged feed-forward RMT pipeline. [37]

## Relationship to DPDK, SPDK and RDMA

DOCA sits above, and exposes, several open-source frameworks. NVIDIA's developer page lists DPDK, SPDK and Linux Netlink as industry-standard APIs within the SDK, alongside an RDMA acceleration SDK that includes UCX, UCC, RDMA verbs and GPUDirect. [1] In DOCA 1.0 the DOCA Flow and DPI libraries ran on top of DPDK libraries and BlueField's connection-tracking and regular-expression engines, and SPDK was included for storage. [4] The DOCA Flow programming guide still assumes familiarity with DPDK. [14] The DOCA 3.5.0 release adds "DOCA Bridge," which "removes DOCA dependency on DPDK (for customers who do not need DPDK)." [8] HBN is an example of the Netlink path: Linux networking state is learned through Netlink and pushed into hardware via DOCA APIs. [32]

## Supported hardware

DOCA targets BlueField DPUs and SuperNICs and ConnectX adapters. The DOCA 3.5.0 release notes list bundled firmware for BlueField-3, BlueField-2 and ConnectX-9, ConnectX-8, ConnectX-7, ConnectX-6 Lx/Dx, ConnectX-6, ConnectX-5 and ConnectX-4 Lx, with ConnectX-9 listed at up to 800GbE Ethernet and XDR InfiniBand. [11][50] The DOCA Management Service guide in the same release already documents BlueField-4 DPU and NIC modes and BlueField-4 operating-system images. [36] Functionality depends on the device: NVIDIA notes that ConnectX adapters cannot use libraries such as DPA even when the full DOCA profile is installed. [12]

NVIDIA promises forward compatibility: "applications developed today will consistently run with added performance benefits on all future generations of BlueField." [1] When it launched BlueField-4, NVIDIA said that "through DOCA, applications accelerated on today's BlueField platforms will run seamlessly on BlueField-4." [23]

## Releases, versioning and deprecations

DOCA follows a quarterly release cadence and semantic versioning: major versions introduce incompatible API changes, minor versions add backward-compatible functionality and patch versions fix bugs. APIs are marked either DOCA_EXPERIMENTAL (not guaranteed in future releases) or DOCA_STABLE (supported for the life of the major version). [38] Long-term-support branches are labeled by year, for example 2.5.x (LTS23), 2.9.x (LTS24) and 3.2.x (LTS25), and receive updates after newer feature releases ship. [10]

The DOCA 3.5.0 release notes announce several changes: [8][9]

- DOCA 3.6.0 (October 2026) will be the last release to support ConnectX-4 Lx and ConnectX-5; as an LTS release it will receive bug fixes and CVE fixes for three years. DOCA 4.0 (January 2027) drops those devices.
- DOCA 3.5.0 is the last release supporting the DOCA App Shield library and the DOCA BlueMan and DOCA Flow Inspector services.
- DOCA 4.0 will replace DOCA-Host installation profiles with smaller "Host Packs," and remove system-wide DOCA Flow resource APIs in favor of a per-port resource model.
- The October 2027 DOCA release will be the last to support ConnectX-6 and BlueField-2.

## Licensing and open-source components

DOCA itself is proprietary. The NVIDIA DOCA license agreement grants a non-exclusive, non-transferable license to modify sample and reference source code, use the software to build applications, and distribute API headers, drivers, libraries and sample applications in object code inside an application. It restricts use to "systems with NVIDIA DPUs, NVIDIA SuperNICs or NVIDIA adapter products," bars reverse engineering, and prohibits disclosing benchmarking or performance results about the software to third parties without NVIDIA's written permission. BlueField SNAP software is licensed per networking platform. [18]

Some components are open source. The DOCA 3.5.0 release notes list individual embedded drivers with their own licenses (for example BSD-3-Clause and GPL-based licenses), while others, such as the FlexIO SDK for the DPA, are proprietary. [11] The DOCA Platform Framework is developed on GitHub as NVIDIA/doca-platform under the Apache License 2.0; the repository was created on October 9, 2024. [30][39]

## Security stack

NVIDIA's recent DOCA announcements have centered on security. BlueField runs its own operating system on its own Arm cores, separate from the host, so software on the DPU can monitor and enforce policy even if the host is compromised. NVIDIA calls this "in-silicon security." [7][24]

**DOCA Argus.** Announced on April 28, 2025, Argus runs on a BlueField DPU and uses "hardware-level live machine introspection and NVIDIA DOCA DMA to read selected structures in volatile host memory." It identifies the host's Linux kernel version, applies a matching kernel memory map, decodes processes, threads, binaries (with SHA-256 hashes), command lines and network connections, and passes them through a policy engine that emits events and alerts. It supports x86 and Arm64 hosts and bare-metal, virtual machine and container workloads, and one DPU monitors the compute node it is attached to. [21][31] NVIDIA claims detection "up to 1,000x faster than existing agentless solutions"; SiliconANGLE repeated the figure in its own voice. [21][22] Argus exports telemetry through Fluent Bit and Vector into SIEM, SOAR and XDR tools. [24] DOCA 3.5 added GPU metrics without a host agent and per-container "runtime manifests." [8] Argus overlaps with the older App Shield library, which also reads host memory from the DPU; App Shield is being discontinued after DOCA 3.5. [9][17]

**DOCA Vault.** Introduced for Vera BlueField-4 STX in May 2026, Vault enforces file-level authorization for AI storage inline on BlueField. It works with DOCA SNAP, which intercepts file requests from the host through device emulation, and enriches each request with Argus process context so that policies can allow or block specific processes from opening, reading or writing specific files. [24][25]

**DOCA Flow** acts as the network enforcement layer, for example programming BlueField as a Layer 4 firewall with connection tracking. [24]

NVIDIA says the combined stack delivers "runtime threat detection up to 1,000x faster than software-only approaches while enforcing network and file access policies at speeds up to 800 Gb/s"; these are vendor figures. [24][25]

### Third-party products built on DOCA

| Vendor | Product and DOCA use | Date |
|---|---|---|
| Check Point | AI Cloud Protect on BlueField-3 uses "the unique direct memory access of NVIDIA DOCA Argus" for host-level visibility; Check Point said it would also run on BlueField-4 | October 28, 2025 [40] |
| Trend Micro | Trend Vision One AI Factory EDR runs an agent on BlueField and consumes DOCA Argus telemetry through Fluent Bit | October 28, 2025 [41] |
| Fortinet | FortiGate VM firewall running on BlueField-3; Fortinet's announcement does not mention DOCA, but its deployment guide (whose example uses a FortiOS 7.6.3 ARM64 image) has users install DOCA-Host on the server | December 16, 2025 [42][43] |
| Cisco | Cisco Secure AI Factory with NVIDIA integrates BlueField and DOCA Argus | April 28, 2025 [21][22] |
| Palo Alto Networks | Prisma AIRS AI Runtime Security on BlueField, drawing on the Sentry reference design and using DOCA Argus for agent introspection | September 28, 2026 [44] |

At the BlueField-4 launch, NVIDIA said Armis, Check Point, Cisco, F5, Forescout, Palo Alto Networks and Trend Micro were building solutions on BlueField and planned to integrate BlueField-4, and that Akamai, [CoreWeave](https://aiwiki.ai/wiki/coreweave), Crusoe, Lambda, Nebius, Oracle Cloud Infrastructure, Together.ai and xAI were "building on NVIDIA DOCA microservices." [23] The May 2026 STX announcement listed Akamai, Armis from ServiceNow, Check Point, Cisco, CrowdStrike, EQTY, F5, Fortinet, Palo Alto Networks, TrendAI, Xage Security and Zscaler as cybersecurity companies integrating with Vera BlueField-4 STX. [25]

## BlueField-4 and Vera Rubin

BlueField-4, announced on October 28, 2025 (NVIDIA said it expected early availability as part of Vera Rubin platforms in 2026), combines an NVIDIA [Grace](https://aiwiki.ai/wiki/nvidia_grace) CPU with ConnectX-9 networking. NVIDIA says it offers six times the compute of BlueField-3 and has native support for DOCA microservices, which it describes as containerized services that secure, scale and simplify AI deployment and operations, along with native service function chaining. [23] NVIDIA's DOCA product page now describes DOCA as "the unified software platform" for "agentic AI infrastructure" and links it to NVIDIA's Scale-In network architecture and to BlueField-4 STX storage. [2]

In the [Vera Rubin](https://aiwiki.ai/wiki/nvidia_vera_rubin) platform, NVIDIA says BlueField-4 is embedded in every compute and storage system, including Vera Rubin NVL72 compute trays, Vera CPU compute trays, LPX systems and Vera BlueField-4 STX storage, giving DOCA services a consistent place to run across the rack. [24] For inference, NVIDIA's CMX context memory storage platform uses a DOCA framework called DOCA Memos, which NVIDIA says "introduces a KV communication and storage layer that treats context cache as a first class resource" and works with [NVIDIA Dynamo](https://aiwiki.ai/wiki/nvidia_dynamo) and NIXL to share [KV cache](https://aiwiki.ai/wiki/kv_cache) across AI nodes. [26] NVIDIA said STX-based platforms from partners were expected in the second half of 2026. [25]

## Role in agent safety (2026)

On September 28, 2026, NVIDIA announced the [NVIDIA Open Agent Safety Platform](https://aiwiki.ai/wiki/nvidia_open_agent_safety_platform), which pairs [NVIDIA OpenShell](https://aiwiki.ai/wiki/nvidia_openshell) agent-sandboxing software on [Vera CPUs](https://aiwiki.ai/wiki/nvidia_vera_cpu) with NVIDIA Sentry, a reference system design for an out-of-band watchdog on BlueField-4 DPUs. [28][29] The press release says: "Sentry is built on NVIDIA DOCA software, which provides the programmable capabilities Sentry uses to inspect agent requests and responses, provide attested telemetry, verify agent identity and enforce granular, zero-trust access policies for data, tools, application programming interfaces and services." [28] NVIDIA's accompanying technical blog says "NVIDIA DOCA makes the BlueField security foundation programmable and connects it with OpenShell policy," and that a "DOCA gateway" adds identity governance, "continuously verifying each agent's identity and delegated authority." [29] The blog calls Sentry an "optional security layer" and says that for systems already running Vera with BlueField-4, enabling the protections "is just a software update." [29] SecurityWeek described Sentry as an optional out-of-band monitor within the platform's reference system design, and Help Net Security wrote that it "is part of the platform's reference system design and requires supported hardware." [45][46]

The press release also says Red Hat "runs OpenShell and DOCA, both part of NVIDIA Open Agent Safety Platform, on Red Hat AI Factory with NVIDIA." [28] Palo Alto Networks described its Prisma AIRS AI Runtime Security firewall on BlueField, which it said draws on the Sentry reference design, on the same day and said it planned an agent identity broker service on BlueField. [44]

## Independent research

Researchers have used DOCA to study BlueField offloads:

- Chen et al. (2024) published what they called the first architectural characterization of the BlueField-3 DPA. They found it "significantly wimpier than the off-path Arm processor and the host CPU," noted that only 190 of 256 DPA threads could run concurrently under the DOCA 2.5.0 driver, and proposed programming guidelines that raised throughput in a key-value aggregation case study by up to 4.3 times. [47]
- Schrötter, Heimbrodt and Schnor (2025) built XenoFlow, a DNS load balancer using the DOCA Flow API on the BlueField-3 eSwitch. It did not reach line rate "with only 2 entries in a Flow Pipe" but had 44% lower latency than a comparable eBPF load balancer on the host. [48]
- Wahlgren et al. (2024) built SODA, a disaggregated-memory system on BlueField, and compared RDMA through ibverbs with DMA through the DOCA SDK for host-to-DPU transfers, reporting up to a 7.9x speedup over node-local SSD on graph workloads. [49]

## References

1. NVIDIA Developer, "DOCA Software Framework." https://developer.nvidia.com/networking/doca
2. NVIDIA, "Agentic AI Infrastructure Software: NVIDIA DOCA." https://www.nvidia.com/en-us/networking/products/software/doca/
3. NVIDIA Newsroom, "NVIDIA Introduces New Family of BlueField DPUs to Bring Breakthrough Networking, Storage and Security Performance to Every Data Center." October 5, 2020. https://nvidianews.nvidia.com/news/nvidia-introduces-new-family-of-bluefield-dpus-to-bring-breakthrough-networking-storage-and-security-performance-to-every-data-center
4. John Kim and Ariel Kit, NVIDIA Technical Blog, "Accelerating Solution Development with DOCA on NVIDIA BlueField DPUs." April 12, 2021. https://developer.nvidia.com/blog/accelerating-solution-development-with-doca-on-bluefield-dpus/
5. Itay Ozery and Scott Ciccone, NVIDIA Technical Blog, "Transform the Data Center for the AI Era with NVIDIA DPUs and NVIDIA DOCA." March 21, 2023. https://developer.nvidia.com/blog/transform-the-data-center-for-the-ai-era-with-nvidia-dpus-and-nvidia-doca/
6. NVIDIA Docs, "DOCA Documentation v3.5.0." https://docs.nvidia.com/doca/sdk/index.html
7. NVIDIA Docs, "DOCA Framework" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-framework
8. NVIDIA Docs, "Changes and New Features" (DOCA 3.5.0 release notes). https://docs.nvidia.com/doca/archive/3-5-0/changes-and-new-features
9. NVIDIA Docs, "Customer Affecting Changes" (DOCA 3.5.0 release notes). https://docs.nvidia.com/doca/archive/3-5-0/customer-affecting-changes
10. NVIDIA Developer, "NVIDIA DOCA LTS Downloads and Previous Releases." https://developer.nvidia.com/doca-archive
11. NVIDIA Docs, "General Support" (DOCA 3.5.0 release notes). https://docs.nvidia.com/doca/archive/3-5-0/general-support
12. NVIDIA Docs, "DOCA Profiles" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-profiles
13. NVIDIA Docs, "DOCA SDK Architecture" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-sdk-architecture
14. NVIDIA Docs, "DOCA Flow" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-flow
15. NVIDIA Docs, "DOCA GPUNetIO" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-gpunetio
16. NVIDIA Docs, "DPA Subsystem" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/dpa-subsystem
17. NVIDIA Docs, "DOCA App Shield" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-app-shield
18. NVIDIA Docs, "DOCA EULA" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-eula
19. NVIDIA Docs, "DOCA Services" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-services
20. David Wills, NVIDIA Technical Blog, "Powering the Next Frontier of Networking for AI Platforms with NVIDIA DOCA 3.0." June 25, 2025. https://developer.nvidia.com/blog/powering-the-next-frontier-of-networking-for-ai-platforms-with-nvidia-doca-3-0/
21. NVIDIA Blog, "NVIDIA Brings Cybersecurity to Every AI Factory." April 28, 2025. https://blogs.nvidia.com/blog/cybersecurity-ai-factory-doca-argus/
22. Duncan Riley, SiliconANGLE, "Nvidia introduces DOCA Argus to bring real-time threat detection to AI infrastructure." April 28, 2025. https://siliconangle.com/2025/04/28/nvidia-introduces-doca-argus-bring-real-time-threat-detection-ai-infrastructure/
23. NVIDIA Blog, "NVIDIA Launches BlueField-4: The Processor Powering the Operating System of AI Factories." October 28, 2025. https://blogs.nvidia.com/blog/bluefield-4-ai-factory/
24. Ofir Arkin, Uriya Stern and Itay Ozery, NVIDIA Technical Blog, "Advancing AI Infrastructure for Agentic AI with NVIDIA DOCA In-Silicon Security." May 31, 2026. https://developer.nvidia.com/blog/advancing-ai-infrastructure-for-agentic-ai-with-nvidia-doca-in-silicon-security/
25. NVIDIA Newsroom, "NVIDIA Vera BlueField-4 STX Brings Agentic AI Storage Processing With In-Silicon Security." May 31, 2026. https://nvidianews.nvidia.com/news/nvidia-vera-bluefield-4-stx-brings-agentic-ai-storage-processing-with-in-silicon-security
26. Moshe Anschel, Einav Zilberstein, Oren Duer, Kirill Shoikhet and Ronil Prasad, NVIDIA Technical Blog, "Introducing NVIDIA BlueField-4-Powered CMX Context Memory Storage Platform for the Next Frontier of AI." March 16, 2026. https://developer.nvidia.com/blog/introducing-nvidia-bluefield-4-powered-inference-context-memory-storage-platform-for-the-next-frontier-of-ai/
27. NVIDIA Docs, "DOCA Overview" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-overview
28. NVIDIA Newsroom, "NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment." September 28, 2026. https://nvidianews.nvidia.com/news/open-agent-safety-platform
29. John Myers, Alex Watson, Ali Golshan and Ofir Arkin, NVIDIA Technical Blog, "NVIDIA Open Agent Safety Platform: A Reference for Continuous In-Silicon Agent Monitoring." September 28, 2026. https://developer.nvidia.com/blog/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring/
30. NVIDIA Docs, "DOCA Platform Framework (DPF)" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-platform-framework-dpf
31. NVIDIA Docs, "DOCA Argus Service Guide" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-argus-service-guide
32. NVIDIA Docs, "DOCA HBN Service Guide" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-hbn-service-guide
33. NVIDIA Docs, "DOCA SNAP Services" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-snap-services
34. NVIDIA Docs, "DOCA Telemetry Service Guide" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-telemetry-service-guide
35. NVIDIA Docs, "DOCA Firefly Service Guide" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-firefly-service-guide
36. NVIDIA Docs, "DOCA Management Service Guide" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-management-service-guide
37. NVIDIA Docs, "DOCA Pipeline Language Services Guide" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-pipeline-language-services-guide
38. NVIDIA Docs, "DOCA SDK Compatibility Policy" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-sdk-compatibility-policy
39. NVIDIA, "doca-platform" GitHub repository. https://github.com/NVIDIA/doca-platform
40. Check Point Software, "Check Point Redefines AI Security for Enterprises with AI Cloud Protect Powered by NVIDIA BlueField." October 28, 2025. https://www.checkpoint.com/press-releases/check-point-redefines-ai-security-for-enterprises-with-ai-cloud-protect-powered-by-nvidia-bluefield/
41. Trend Micro, "AI Security: NVIDIA BlueField Now with Vision One." October 28, 2025. https://www.trendmicro.com/en/research/25/j/ai-security-nvidia-bluefield.html
42. Fortinet, "Fortinet Delivers Isolated Infrastructure Acceleration for the AI Factory with NVIDIA." December 16, 2025. https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2025/fortinet-delivers-isolated-infrastructure-acceleration-for-the-ai-factory-with-nvidia
43. Fortinet Document Library, "FortiGate-VM on NVIDIA BlueField-3" (FortiGate Private Cloud 7.6.0). https://docs.fortinet.com/document/fortigate-private-cloud/7.6.0/bluefield-3-deployment-guide/489491/fortigate-vm-on-nvidia-bluefield-3
44. Anand Oswal, Palo Alto Networks Blog, "Securing AI Agents at Scale with NVIDIA." September 28, 2026. https://www.paloaltonetworks.com/blog/2026/09/securing-ai-agents-at-scale-with-nvidia/
45. Eduard Kovacs, SecurityWeek, "Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog." September 28, 2026. https://www.securityweek.com/nvidia-unveils-ai-agent-safety-platform-with-hardware-based-watchdog/
46. Anamarija Pogorelec, Help Net Security, "NVIDIA wants AI agent safety enforced in silicon, not left to the agent." September 28, 2026. https://www.helpnetsecurity.com/2026/09/28/nvidia-open-agent-safety-platform/
47. Xuzheng Chen et al., "Demystifying Datapath Accelerator Enhanced Off-path SmartNIC." arXiv:2402.03041, 2024. https://arxiv.org/abs/2402.03041
48. Max Schrötter, Sten Heimbrodt and Bettina Schnor, "XenoFlow: How Fast Can a SmartNIC-Based DNS Load Balancer Run?" arXiv:2509.21656, 2025. https://arxiv.org/abs/2509.21656
49. Jacob Wahlgren, Gabin Schieffer, Maya Gokhale, Roger Pearce and Ivy Peng, "Disaggregated Memory with SmartNIC Offloading: a Case Study on Graph Processing." arXiv:2410.02599, 2024. https://arxiv.org/abs/2410.02599
50. NVIDIA Docs, "DOCA Release Notes" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-release-notes
51. NVIDIA Docs, "DOCA Rivermax" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-rivermax
52. NVIDIA Docs, "DOCA UROM" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-urom
53. NVIDIA Docs, "DOCA STA" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-sta
54. NVIDIA Docs, "DOCA Device Emulation" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-device-emulation
55. NVIDIA Docs, "DOCA Telemetry" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-telemetry
56. NVIDIA Docs, "DOCA XPlane Service Guide" (DOCA 3.5.0). https://docs.nvidia.com/doca/archive/3-5-0/doca-xplane-service-guide

