Redundancy & Common-Cause Failure Prevention
Beyond Just "Have Multiple Sensors"
Module 5.1 mentioned redundant speed pickups for overspeed protection, and Module 4.6 briefly introduced 2-out-of-3 voting logic. This module goes deeper into both — the actual trade-offs different voting architectures involve, and the equally important question of common-cause failure: what good is redundancy if all the redundant sensors can fail together for the same reason?
Voting Architectures — The Trade-Off Space
A 1oo1 (1-out-of-1) architecture relies on a single sensor — simplest and cheapest, but offering no protection against that one sensor's failure in either direction: a falsely high reading causes a spurious trip, while a failure to detect real danger provides no protection at all.
A 2oo2 (2-out-of-2) architecture requires both of two independent sensors to agree before tripping, reducing spurious trips from a single sensor malfunction. But this maximizes "trip security" (avoiding nuisance trips) at a real cost to "trip availability" (ensuring genuine dangers are always caught) — if either sensor fails in a way that prevents it from confirming a real danger, the required second confirmation might never arrive.
A 2oo3 (2-out-of-3) architecture uses three independent sensors and trips if any two agree — a majority-vote structure often considered the best practical balance. A single failed sensor, reading either falsely high or falsely low, doesn't prevent the other two from correctly detecting a genuine trip condition, and it doesn't cause a spurious trip on its own either, since two-out-of-three agreement is still required.
There's a genuine, unavoidable trade-off between trip security (avoiding spurious trips) and trip availability (never missing a real danger). No voting architecture maximizes both simultaneously — engineering judgment about the specific consequences of each type of failure for that particular function determines the right choice.
The Problem Voting Alone Doesn't Solve — Common-Cause Failure
Even a well-designed 2oo3 voting architecture provides limited protection if all three sensors can fail together for the same underlying reason — a common-cause failure. Three sensors provide no real additional protection if a single localized event can disable all three simultaneously because they're bundled together.
Physical separation — different locations, different cable routing, different junction boxes for redundant sensors — prevents a single localized event (fire, physical damage, water intrusion) from simultaneously disabling multiple sensors meant to provide independent confirmation. Independent power supplies extend this same principle to power sourcing: redundant protective paths drawing from genuinely separate power sources means a single power supply failure can't disable multiple backup paths at once — extending Module 3.4's system independence principle all the way down to the power source level, since a shared supply is itself a potential single point of common-cause failure.
Redundancy that isn't also protected against common-cause failure can create a false sense of security. Three sensors sound like strong protection, but if they share a cable tray, a junction box, or a power supply, a single event could still disable all three at once — the voting logic alone wouldn't help.
The Deepest Layer — Design Diversity
Some critical redundant systems intentionally use components from different manufacturers or different underlying designs, so a design flaw or manufacturing defect specific to one product line can't simultaneously compromise every redundant unit relying on identical components. This is the most sophisticated layer of common-cause failure prevention — even physically separated, independently powered sensors could still share an undiscovered design flaw if they're identical products, which is why some critical applications deliberately introduce this kind of diversity as well.