control//fault-tolerant control//redundancy//majority voting
Majority voting is a fault-tolerance technique in which several redundant channels compute or measure the same quantity and the system uses the value most of them agree on, so that one faulty channel is outvoted and isolated; with three channels it is called **triple modular redundancy** or two-out-of-three (2oo3) voting. It is what turns redundancy from detection into isolation. Two identical sensors reveal that they differ but not which one is right; three let the vote name the faulty one.
Majority voting is a fault-tolerance technique in which several redundant channels compute or measure the same quantity and the system uses the value most of them agree on, so that one faulty channel is outvoted and isolated; with three channels it is called triple modular redundancy or two-out-of-three (2oo3) voting. It is what turns redundancy from detection into isolation. Two identical sensors reveal that they differ but not which one is right; three let the vote name the faulty one.
For continuous signals the vote is usually the median: of three airspeed readings, the middle one ignores a channel that has gone wild, however large its error. If each channel survives the mission independently with probability RRR, the system survives when at least two do:
R2oo3=R3+3R2(1−R)=3R2−2R3.R_{2oo3}=R^3+3R^2(1-R)=3R^2-2R^3.R2oo3=R3+3R2(1−R)=3R2−2R3.
The first term is all three healthy, the second exactly one failed, in three possible ways. With R=0.99R=0.99R=0.99 the result is about 0.9997: the probability of failure drops from 1 % to 0.03 %.
The formula hangs on one word, independent.
Three probes that ice up together or three copies of one buggy program fail as one, and then the vote is unanimous and wrong (common-mode failure). The formula also has small print: if R<0.5R<0.5R<0.5, voting is worse than a single channel, since a majority of bad units outvotes the good one.
Voting needs a tolerance. Healthy channels never agree exactly (noise, mounting, small calibration differences, sampling at slightly different instants), so the voter declares a channel failed only when it departs from the others by more than a threshold, held for some time; set it too tight and healthy sensors are voted out, too loose and a slow drift passes (detection threshold).
After one failure the vote degrades to two channels, which can detect a second fault but no longer isolate it; designs state what happens then (a degraded mode, or a fourth channel).
The same arithmetic runs in safety systems as k-out-of-n architectures: a 1oo2 trip (either sensor trips) favours safety and gives more spurious trips; a 2oo3 trip balances safety against availability (safety instrumented system).
Voting among computers is the oldest form: three processors run the same task and compare outputs, the scheme used in flight computers and spacecraft. Distributed systems that must agree despite nodes that lie need more, at least 3f+13f+13f+1 nodes for fff malicious ones (resilient consensus).