In this paper, we propose a zero-knowledge proof scheme of shuffle. Unlike the previous schemes, our scheme can be used as the shuffle of the elements encrypted by Paillier's encryption scheme, which has an additive homomorphic property in the message part. The ElGamal encryption scheme, used in the previous schemes, does not have this property.