“…Roughly speaking, there are two kinds of proof system of mix-nets; one is optimistic and the other is verifiable proof system. The correctness of the shuffling of the whole mix-net is verified after the mix-net outputs the shuffling results in plain texts in optimistic proof system [17], while in verifiable proof system each mix server provides proofs of correctness of the shuffling [28,14,1,18,22,23,27,33].…”