D-2.8 Homomorphic Key Switching

BFV’s key switching scheme changes an RLWE ciphertext’s secret key from S to S. This scheme is essentially RLWE’s key switching scheme with the sign of the A S term flipped in the encryption and decryption formula. Specifically, this is equivalent to the alternative GLWE version’s (§B-4.4) key switching scheme (§C-5) with k = 1 as follows:

Summary D-2.8 BFV’s Key Switching

𝖱𝖫𝖶𝖤S,σ(ΔM) = (0,B) + 𝖣𝖾𝖼𝗈𝗆𝗉β,l(A), 𝖱𝖫𝖾𝗏S,σβ,l(S)