In this paper, we propose a zero-knowledge proof scheme of shuffle. Unlike the previous schemes, our scheme can be used as the shuffle of the elements that are encrypted from Paillier's cryptosystem. The Paillier's encryption scheme has an additive homomorphic property. The ElGamal cryptosystem, used in the previous works, does not have this property.