Orbitra Prime
Trading intelligence
Orbitra Prime accounts, API keys and institutional signers follow Q-Switch suites. Rotation and migration appear as guided account actions, not as a forced exchange of assets.
Cryptographic agility system
Every signature on a blockchain depends on an algorithm that may one day need replacing. Q-Switch is the cryptographic-agility system of Orbitra L1: signature suites are versioned, credentials can be hybrid — classical and post-quantum together — and keys and addresses rotate and migrate under protocol rules as standards, libraries and hardware mature.
How it moves
Suite v1 · classical
Suite v2 · hybrid
Suite v3 · post-quantum ready
The illustration shows three versioned signature suites side by side: a classical suite, a hybrid suite and a post-quantum-ready suite. An account moves from the classical suite to a hybrid credential that combines classical and post-quantum-ready signatures, rotates its keys and migrates its address, carrying its assets and history through every step.
The problem
Many networks fix one signature algorithm into their account model. Addresses are derived from it, wallets assume it and validators verify nothing else. Replacing it later becomes a disruptive, network-wide event — usually decided under pressure.
The cryptographic landscape is moving. A sufficiently large quantum computer would undermine the public-key schemes in widespread use today. Keys whose public halves are already visible on a ledger would be the most exposed, and encrypted traffic recorded now could be decrypted later. Post-quantum signature and key-exchange standards are emerging, while libraries, hardware support and operational practice continue to mature.
Q-Switch turns cryptographic change into a governed, routine operation. Every key and signature identifies its suite, accounts can carry hybrid credentials through a transition, and migration paths for keys and addresses are part of the protocol — so adopting stronger algorithms is controlled rather than improvised.
Operating sequence
The same sequence applies to a personal wallet, an institutional signer and a validator’s consensus key.
Every key, signature and address records the suite that produced it. Verifiers select the algorithm from the suite identifier instead of assuming one.
A new suite enters the protocol through a governed upgrade once its specification, implementations and hardware support are mature enough to rely on.
Accounts and validators bind a classical and a post-quantum key to the same identity. Where policy requires both signatures, the credential stays secure as long as either algorithm holds.
Keys rotate under account policy while the account itself stays the same. A successor can be committed in advance, so rotation never depends on a key that may already be weakened.
Assets, positions and permissions move from an address bound to an older suite to one bound to a newer suite, in a single recorded transition that links the two.
Older suites are restricted in stages — first for new keys, later for all use — under governed rules and with notice, so no holder is locked out by a sudden change.
Architecture
Q-Switch is less a single algorithm than a set of rules that let algorithms be exchanged safely — across accounts, validators and the network itself.
The protocol’s list of admitted signature and key-exchange suites, each with a version identifier, parameters and a status: active, admitted for hybrid use or being retired.
Transaction, vote and credential verification dispatch on the suite identifier, so admitting a suite changes configuration rather than the account model.
Binds a classical and a post-quantum public key to one identity and enforces the signature policy the account or role requires, up to dual signatures for the most sensitive authority.
Rotates account, institutional and validator keys under policy, with pre-committed successors and multi-party approval available for high-value accounts and QSE consensus keys.
Links an old address to its successor so assets, positions, permissions and VaultID credentials transfer in one recorded transition.
Validator links, regional gateways and GateMesh connections negotiate key-exchange suites by version, so encrypted transport can adopt hybrid protection without a protocol redesign.
Security and failure control
Changing cryptography is itself a security event. Q-Switch is designed so that every transition is deliberate, staged and verifiable.
Across the three systems
Orbitra Prime
Trading intelligence
Orbitra Prime accounts, API keys and institutional signers follow Q-Switch suites. Rotation and migration appear as guided account actions, not as a forced exchange of assets.
Orbitra L1
Settlement and compute
Q-Switch spans Orbitra L1: transaction signatures, QSE validator votes, historical records and encrypted network transport all resolve their cryptography through versioned suites.
Orbitra Realm
Applications and commerce
Applications, VaultID credentials and AI agents in Orbitra Realm inherit agility from the network instead of implementing it themselves. A credential anchored to one suite today can move to another through the same migration path.
Value
Specifications
Q-Switch provides the mechanisms for a controlled cryptographic transition. Specific post-quantum algorithms are adopted as standards, libraries and hardware mature; no certification is implied.
Terminology