[prev][parent][next]
To recover the message M, it is sufficient to decrypt the last GLev ciphertext (the one encrypting M) using the secret S. Decrypting the other rows yields −Si ⋅M, but recovering M from these rows is only possible if Si is invertible (i.e., Si≠0).