We show that, after a constant-round preprocessing stage, it is possib
le for a prover to prove knowledge of a witness for any polynomial-tim
e relation without any further interaction. The number of proofs that
can be given is not bounded by any fixed polynomial in the size of the
preprocessing. Our construction is based on the sole assumption that
one-way functions and noninteractive zero-knowledge proof systems of m
embership exist.