A-6.4 Gadget Decomposition

Gadget decomposition is a generalized form of number decomposition (§A-6.1). In number decomposition, a number γ is decomposed as follows:

γ = γ1 q β1 + γ2 q β2 + + γl q βl

In gadget decomposition, we decompose γ as follows:

γ = γ1g1 + γ2g2 + + γlgl

We denote g = (g1,g2,,gl) as a gadget vector, and 𝖣𝖾𝖼𝗈𝗆𝗉g(γ) = (γ1,γ2, , γl)

Then, γ = 𝖣𝖾𝖼𝗈𝗆𝗉g(γ),g

In the case of number decomposition (§A-6.1), its gadget vector is g = ( q β, q β2,, q βl).