control//fault-tolerant control//redundancy

Redundancy is the provision of more than one unit able to do the same job, so that a failure of one is detected and survived, and it is the raw material of every fault-tolerant system, from three pitot probes on an airliner to two pressure transmitters on a reactor. What redundancy buys depends on the count: **two units detect, three isolate**. Two sensors that disagree tell you something is wrong but not which one is lying; three let a vote decide (majority voting).


Redundancy is the provision of more than one unit able to do the same job, so that a failure of one is detected and survived, and it is the raw material of every fault-tolerant system, from three pitot probes on an airliner to two pressure transmitters on a reactor. What redundancy buys depends on the count: two units detect, three isolate. Two sensors that disagree tell you something is wrong but not which one is lying; three let a vote decide (majority voting).

It comes in three kinds. Physical redundancy puts two or three identical sensors or actuators side by side and compares them: robust and simple, but it costs money, weight, wiring and power, which on a drone or a satellite is a real budget. Dissimilar redundancy uses different designs for the same function (different processors, different software written by different teams, sensors on different physical principles) so that one design error or one environmental cause cannot take them all down; fly-by-wire flight computers are the reference. Analytical redundancy uses a model as the second unit: with a pump's curve, speed and flow predict the pressure, and the predicted value checks the transmitter without a second transmitter.

Redundancy is worth only its independence.

Three identical probes that freeze in the same ice, three channels powered from one supply, or three copies of the same software with the same bug fail together. That common-mode failure turns triple redundancy into one expensive bet, and it is the reason dissimilarity costs what it costs.

Redundancy needs diagnosis to be useful. Without a comparison, a vote or a residual, a spare unit silently does nothing while the failed one drives the loop (fault diagnosis).

Redundancy in a fleet is units rather than parts: losing one drone of fifty is a degraded mission, not a lost one, provided the tasks can be reassigned.

Redundancy against an attacker is weaker than against nature: a competent attacker forges several sensors at once, so independent physical measurements outside the network count for more than extra copies of the same one (resilient control).

Each redundant unit is also a new thing to fail and to maintain, and the comparison logic itself is a single point of failure if it is not designed with the same care; what the extra units buy is counted as availability.