In the RLWE cryptosystem, the formula in Summary B-1.2 is the same, but are replaced by polynomials as follows:
Summary B-1.3 Lattice-based RLWE Cryptosystem
Encryption: , where and are publicly known also to the attacker, while are unknown (only known by the secret key owner).
Decryption:
provided
,
meaning each coefficient of
has a magnitude less than
is equivalent to rounding each term’s coefficient in the polynomial.