Skip to content
ORBITRAONE
Q-SwitchOrbitra L1

Cryptographic agility system

Cryptography that can change without breaking trust.

Every signature on a blockchain depends on an algorithm that may one day need replacing. Q-Switch is the cryptographic-agility system of Orbitra L1: signature suites are versioned, credentials can be hybrid — classical and post-quantum together — and keys and addresses rotate and migrate under protocol rules as standards, libraries and hardware mature.

How it moves

Three suites, one continuous account

Illustration: Signature suites are versioned. An account moves from a classical suite to a hybrid credential that combines classical and post-quantum-ready signatures, rotates its keys and migrates its address without losing its history or assets.

Suite v1 · classical

Suite v2 · hybrid

Suite v3 · post-quantum ready

  1. 01Versioned suites
  2. 02Hybrid credentials
  3. 03Key rotation
  4. 04Address migration

The illustration shows three versioned signature suites side by side: a classical suite, a hybrid suite and a post-quantum-ready suite. An account moves from the classical suite to a hybrid credential that combines classical and post-quantum-ready signatures, rotates its keys and migrates its address, carrying its assets and history through every step.

The problem

Hard-wired cryptography is a long-term liability.

Many networks fix one signature algorithm into their account model. Addresses are derived from it, wallets assume it and validators verify nothing else. Replacing it later becomes a disruptive, network-wide event — usually decided under pressure.

The cryptographic landscape is moving. A sufficiently large quantum computer would undermine the public-key schemes in widespread use today. Keys whose public halves are already visible on a ledger would be the most exposed, and encrypted traffic recorded now could be decrypted later. Post-quantum signature and key-exchange standards are emerging, while libraries, hardware support and operational practice continue to mature.

Q-Switch turns cryptographic change into a governed, routine operation. Every key and signature identifies its suite, accounts can carry hybrid credentials through a transition, and migration paths for keys and addresses are part of the protocol — so adopting stronger algorithms is controlled rather than improvised.

Operating sequence

A cryptographic transition in six controlled steps.

The same sequence applies to a personal wallet, an institutional signer and a validator’s consensus key.

  1. 01

    Version

    Every key, signature and address records the suite that produced it. Verifiers select the algorithm from the suite identifier instead of assuming one.

  2. 02

    Admit

    A new suite enters the protocol through a governed upgrade once its specification, implementations and hardware support are mature enough to rely on.

  3. 03

    Hybridize

    Accounts and validators bind a classical and a post-quantum key to the same identity. Where policy requires both signatures, the credential stays secure as long as either algorithm holds.

  4. 04

    Rotate

    Keys rotate under account policy while the account itself stays the same. A successor can be committed in advance, so rotation never depends on a key that may already be weakened.

  5. 05

    Migrate

    Assets, positions and permissions move from an address bound to an older suite to one bound to a newer suite, in a single recorded transition that links the two.

  6. 06

    Retire

    Older suites are restricted in stages — first for new keys, later for all use — under governed rules and with notice, so no holder is locked out by a sudden change.

Architecture

Components of the agility system

Q-Switch is less a single algorithm than a set of rules that let algorithms be exchanged safely — across accounts, validators and the network itself.

  1. 01

    Suite registry

    The protocol’s list of admitted signature and key-exchange suites, each with a version identifier, parameters and a status: active, admitted for hybrid use or being retired.

  2. 02

    Suite-aware verification

    Transaction, vote and credential verification dispatch on the suite identifier, so admitting a suite changes configuration rather than the account model.

  3. 03

    Hybrid credential binding

    Binds a classical and a post-quantum public key to one identity and enforces the signature policy the account or role requires, up to dual signatures for the most sensitive authority.

  4. 04

    Key rotation service

    Rotates account, institutional and validator keys under policy, with pre-committed successors and multi-party approval available for high-value accounts and QSE consensus keys.

  5. 05

    Address migration

    Links an old address to its successor so assets, positions, permissions and VaultID credentials transfer in one recorded transition.

  6. 06

    Transport agility

    Validator links, regional gateways and GateMesh connections negotiate key-exchange suites by version, so encrypted transport can adopt hybrid protection without a protocol redesign.

Security and failure control

Controlled change, not emergency change.

Changing cryptography is itself a security event. Q-Switch is designed so that every transition is deliberate, staged and verifiable.

  • Defense in depthHybrid credentials that require both classical and post-quantum signatures remain secure if either algorithm alone is unexpectedly weakened.
  • Governed admissionNew suites are admitted only through protocol governance after specification and review — never by a single operator switching algorithms.
  • Downgrade protectionOnce an account or connection has moved to a stronger suite, signatures and handshakes from weaker suites are rejected for it.
  • Recorded transitionsEvery rotation and migration is an onchain transition with its own evidence, so the key history of any account can be reconstructed end to end.
  • Separated key domainsAccount, validator, custody and transport keys are distinct and rotate independently, so a transition in one domain does not force change in all of them.

Across the three systems

Agility across Prime, L1 and Realm

Orbitra Prime

Trading intelligence

Orbitra Prime accounts, API keys and institutional signers follow Q-Switch suites. Rotation and migration appear as guided account actions, not as a forced exchange of assets.

Orbitra L1

Settlement and compute

Q-Switch spans Orbitra L1: transaction signatures, QSE validator votes, historical records and encrypted network transport all resolve their cryptography through versioned suites.

Orbitra Realm

Applications and commerce

Applications, VaultID credentials and AI agents in Orbitra Realm inherit agility from the network instead of implementing it themselves. A credential anchored to one suite today can move to another through the same migration path.

Value

Why agility matters to each audience

Traders and users
Long-lived assets and identity that do not depend on one algorithm lasting forever. If migration is needed, it happens inside your account, with balances and history intact.
Institutions
A credible answer to cryptographic-transition risk. Versioned suites, hybrid credentials and recorded migrations give security teams a controlled path they can evaluate, govern and evidence. See security.
Developers
Suite-aware interfaces from the start. NexusSDK signing, verification and key exchange take a suite identifier, so applications built now keep working as new suites are admitted.

Specifications

Specifications

Scope
Account signatures, validator keys, credentials and network transport
Suite model
Versioned suites identified in every key, signature and address
Hybrid credentials
Classical and post-quantum keys bound to one identity
Key rotation
Policy-driven, with pre-committed successors and multi-party approval options
Address migration
One recorded transition moves assets, positions and permissions to a new-suite address
Suite admission
Through protocol governance, aligned with the direction of NIST post-quantum standardization
Downgrade protection
Weaker suites rejected once an account or connection has moved forward
Interfaces
Post-quantum-ready signing, verification and key-exchange interfaces in NexusSDK

Q-Switch provides the mechanisms for a controlled cryptographic transition. Specific post-quantum algorithms are adopted as standards, libraries and hardware mature; no certification is implied.

Terminology

Terminology

Cryptographic agility
The ability to replace cryptographic algorithms without redesigning the systems that depend on them.
Signature suite
A versioned combination of algorithm, parameters and encoding, referenced by an identifier.
Hybrid credential
A credential that binds a classical and a post-quantum key. When both signatures are required, it stays secure as long as either algorithm holds.
Key rotation
Replacing a key with a successor while the account, its assets and its permissions stay the same.
Address migration
Moving an account’s holdings and rights from an address tied to one suite to an address tied to another.
Downgrade attack
An attempt to force a system back to a weaker algorithm it has already moved beyond.

ONE NETWORK. INFINITE MARKETS.

Apply for access to ORBITRA ONE™.