Let the size of plaintext, and the size of ciphertext, where ( is much smaller than ) and (i.e., divides ). Randomly pick a -degree polynomial whose coefficients are either as a secret key. Let the scaling factor of plaintext.
Notice that RLWE’s setup parameters are similar to that of LWE. One difference is that is not a vector of length sampled from , but an -degree polynomial encoding secret coefficients, where each coefficient is a randomly picked ternary number from (denoted as ).