[prev][parent][next]
Suppose we have an (n −1)-degree polynomial M ∈R(n,t) whose coefficients represent the plaintext numbers to encrypt.
The GLWE encryption formula is summarized as follows:
⟨Summary B-4.2⟩ GLWE Encryption
Initial Setup: Δ = ⌊q t⌋, {Si}i=0k−1 ←$R⟨n,2⟩k
Encryption Input: M ∈R⟨n,t⟩, {Ai}i=0k−1 ←$R⟨n,q⟩k, E ←χσR⟨n,q⟩