<p><b>Abstract</b>—A specification language used in the context of an effective theorem prover can provide novel features that enhance precision and expressiveness. In particular, typechecking for the language can exploit the services of the theorem prover. We describe a feature called "predicate subtyping" that uses this capability and illustrate its utility as mechanized in PVS.</p>
Sam Owre, John Rushby, Natarajan Shankar, "Subtypes for Specifications: Predicate Subtyping in PVS", IEEE Transactions on Software Engineering, vol. 24, no. , pp. 709-720, September 1998, doi:10.1109/32.713327
