# Confusion with BGV

**URL:** <https://openfhe.discourse.group/t/confusion-with-bgv/1587>\
**Category:** FHE Questions\
**Created:** [September 18, 2024, 5:06pm UTC](https://openfhe.discourse.group/t/confusion-with-bgv/1587 "2024-09-18T17:06:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sp18](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@sp18](https://openfhe.discourse.group/u/sp18)\
**Post date:** [September 18, 2024, 5:06pm UTC](https://openfhe.discourse.group/t/confusion-with-bgv/1587/1 "2024-09-18T17:06:17Z")

</div>

In the original BGV paper, the ciphertext contains just one component, whereas here in the library, the BGV implementation as well as in other libraries has 2 ciphertext components per ciphertext. Why is this difference? am I missing something.

---

<div class="post-metadata">

**Author:** ![narger](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/narger/32/420_2.png) [@narger](https://openfhe.discourse.group/u/narger)\
**Post date:** [September 19, 2024, 11:49am UTC](https://openfhe.discourse.group/t/confusion-with-bgv/1587/2 "2024-09-19T11:49:58Z")

</div>

The original BGV paper might assume LWE (actually, GLWE), while 2 components is usually two polynomials, thus RLWE. Perhaps you might look at [this](https://eprint.iacr.org/2021/204)

---

<div class="post-metadata">

**Author:** ![Caesar](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/caesar/32/63_2.png) [@Caesar](https://openfhe.discourse.group/u/Caesar)\
**Post date:** [September 19, 2024, 8:41pm UTC](https://openfhe.discourse.group/t/confusion-with-bgv/1587/3 "2024-09-19T20:41:21Z")

</div>

I am not aware of any “BGV” scheme where the ciphertext includes only one polynomial. Can you share a link to the paper you are referring to?

---

<div class="post-metadata">

**Author:** ![narger](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/narger/32/420_2.png) [@narger](https://openfhe.discourse.group/u/narger)\
**Post date:** [September 20, 2024, 4:08pm UTC](https://openfhe.discourse.group/t/confusion-with-bgv/1587/4 "2024-09-20T16:08:12Z")

</div>

Perhaps they refer to the basic LWE version of BGV, where a ciphertext is a vector {\bf c} \in \mathbb{Z}\_Q^n encrypting a single message [\mu]\_t ?

---

<div class="post-metadata">

**Author:** ![sp18](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@sp18](https://openfhe.discourse.group/u/sp18)\
**Post date:** [September 20, 2024, 5:13pm UTC](https://openfhe.discourse.group/t/confusion-with-bgv/1587/5 "2024-09-20T17:13:56Z")

</div>

The original paper [Here](https://eprint.iacr.org/2011/277.pdf) has just 1 ciphertext component (not polynomial but vector) for the basic scheme (page 7) and leveled scheme (page 11). That’s what confuses me. I know this is the GLWE representation but do not understand how this changes to two components in RLWE space

---

<div class="post-metadata">

**Author:** ![Caesar](https://yyz1.discourse-cdn.com/flex031/user_avatar/openfhe.discourse.group/caesar/32/63_2.png) [@Caesar](https://openfhe.discourse.group/u/Caesar)\
**Post date:** [September 20, 2024, 8:29pm UTC](https://openfhe.discourse.group/t/confusion-with-bgv/1587/6 "2024-09-20T20:29:33Z")

</div>

The paper uses a generic representation that works for both LWE and RLWE rings. Read the first paragraph in Section 2.3 which states the generalization. In the case of RLWE, n=1 and R\_q=\mathbb{Z}\_q / f(x^d+1), and the encryption in Section 3.1 generates a ciphertext in R\_q^2, that is, two components.

Similarly, in the LWE case, where n=poly(\lambda) and R\_q=\mathbb{Z}\_q, the ciphertext has two components as well: a vector in \mathbb{Z}\_q^n and an integer in \mathbb{Z}\_q.
