In the RLWE cryptosystem, the formula in Summary B-1.2 is the same, but are replaced by polynomials as follows:
Summary B-1.3 Lattice-based RLWE Cryptosystem
Encryption: , where and are publicly known also to the attacker, while are unknown (only known by the secret key owner).
Decryption: provided
is equivalent to rounding each term’s coefficient in the polynomial.