C-4.3 Discussion

PIC

Figure 12: An illustration of scaled plaintext with a noise: Δ m + e q

Reduced Distance between m and e: After modulus switching of an LWE ciphertext from q q^, the underlying plaintext (containing a noise) Δm + e gets shrunk to Δ^m + e^, as illustrated in Figure 12. Note that after the modulus switch from q q^, Δm is down-scaled to Δ^m without losing its bit data. Notably, the plaintext value m stays the same after the modulus switch, while its scaling factor Δ gets reduced to Δ^ and the noise e gets reduced to e^. However, after the modulus switch, the distance between e^’s MSB and Δ^m’s LSB gets reduced compared to the distance between e’s MSB and Δm’s LSB.