10.3 Sensor Redundancy & 2-out-of-3 Voting
Key Takeaways
- Critical DP sensors such as gyros are commonly triplicated so a single bad unit can be rejected without losing the measurement function
- 2-out-of-3 (2oo3) voting accepts the consensus of two sensors and rejects a single deviant sensor
- Dual (2-of-2) sensor suites cannot decide which unit is wrong when the two disagree — they can only alarm and force operator or system intervention
- True redundancy requires independent power and data paths so one supply, cable, or network fault does not kill multiple ‘redundant’ sensors together
- Sensor voting is part of Class 2/3 single-fault tolerance for the measurement chain, not a substitute for good PRS diversity
Why sensor redundancy belongs with equipment class
Equipment Class 2 and Class 3 claim that a single active failure should not cause loss of position. That claim is empty if a single gyro, wind sensor, or MRU can silently drive thrusters the wrong way. Redundant sensors and voting are how the measurement chain supports the same single-fault philosophy you learned for generators and thrusters.
This section focuses on environmental and heading sensors (and the general voting idea). Position-reference voting among DGNSS, acoustics, and relative systems is related and is covered deeply in the PRS chapters — the logic is the same family: compare independent measurements, reject the odd one out, keep control stable.
What “critical sensors” means on DP
Typical critical sensor families for closed-loop DP include:
| Sensor | What it feeds | Why single failure hurts |
|---|---|---|
| Gyrocompass(es) | Heading and yaw control; body-frame transforms | Wrong heading → wrong force direction and thruster allocation |
| MRU / VRU | Roll/pitch (and sometimes heave) for lever-arm correction | Antenna/transducer positions mis-compensated → position error |
| Wind sensor(s) | Wind feed-forward force | Wrong feed-forward → thrusters fight phantom wind |
| PRS suite (related) | Position update to the estimator | Bad position → drive-off or large footprint |
Of these, triple gyro installations are the classic textbook example for 2-out-of-3 voting on induction exams.
Triple redundancy — three of a kind
Triple redundancy means three independent sensors of the same type measure the same quantity (for example three gyros measuring heading). Design goals:
- If one sensor fails or drifts, the other two still agree and the system continues with a trustworthy value.
- The failed unit can be alarmed and rejected without the operator instantly losing all heading input.
- Planned maintenance or calibration on one unit need not force a total loss of the function (vessel-specific procedures still apply).
Triple is preferred over dual for voting because three points allow a majority. Two points only allow agreement or disagreement.
2-out-of-3 (2oo3) voting — how it works
2-out-of-3 voting means the system treats a measurement as valid when at least two of three sensors agree within a defined tolerance band. Logic in operator language:
- Read Sensor A, B, and C.
- Compare them pairwise (or compare each to a median / consensus value).
- If two agree and one is outside tolerance → reject the outlier, use the consensus of the two, raise an alarm.
- If all three agree → high confidence, use the voted value (or median).
- If all three disagree (no pair within tolerance) → voting failure / sensor conflict alarm; the system may freeze last good heading, drop to a safe degraded strategy, or demand immediate operator action depending on design.
| Situation | Voting result | DPO action mindset |
|---|---|---|
| 3 agree | Healthy voted value | Monitor; normal ops |
| 2 agree, 1 wild | Reject wild; continue on 2 | Investigate the failed unit; plan repair; note reduced fault tolerance |
| Only 1 healthy online | No true 2oo3 majority left | Degraded — treat as high risk; follow ASOG |
| 0 agree / all conflict | No consensus | Critical — do not ignore; reduce operational risk |
[!IMPORTANT] After one gyro is already rejected, you no longer have full triple redundancy. You may be down to a dual comparison or a single remaining healthy sensor. The next failure can leave you without a trusted heading source. Restore diversity promptly.
Why dual systems cannot truly “vote which is wrong”
With only two sensors (dual redundancy):
- If they agree, confidence is reasonable but you still cannot detect a common-mode error (both wrong the same way).
- If they disagree, the system knows something is wrong but cannot mathematically prove which unit is correct without a third opinion or an independent absolute reference.
| Suite | When they agree | When they disagree |
|---|---|---|
| Dual (2 sensors) | Use either/average with caution; common-mode still possible | Conflict alarm — cannot vote out the bad one automatically with majority logic |
| Triple (3 sensors) | Strong consensus | Majority can reject the single deviant |
Exam phrase to remember: two sensors can detect a split; three sensors can vote out a single rogue.
Designers sometimes use dual sensors with additional checks (rate-of-change limits, comparison to model estimate, comparison to PRS-derived course). Those are useful quality tests, but they are not the same as clean 2oo3 majority voting. On the exam, prefer the clean statement of dual’s limit unless the question describes extra logic.
Independence of power and data paths
Sticking three gyro boxes on one shelf, fed by one fuse and one network switch, is cosmetic redundancy. True sensor redundancy for Class 2/3 thinking requires independence:
| Independence dimension | Bad (common-mode) | Better |
|---|---|---|
| Electrical power | All three on one UPS or one breaker | Separate UPS feeds / power partitions aligned with redundancy groups |
| Data path | All three on one network switch/cable trunk | Separate networks, ports, or routes so one cable fire does not silence all |
| Physical location | All in one cabinet in one room | Separation consistent with class (especially Class 3 compartment thinking) |
| Configuration / software | Same wrong setup copied to all | Controlled change; avoid simultaneous misconfiguration |
| Environment | All subject to same magnetic/heat damage without protection | Installation standards and separation reduce shared insults |
If one power failure blacks all three “redundant” gyros, the vessel effectively has zero heading sensors — the opposite of single-fault tolerance. FMEA and DP trials specifically look for these hidden common connections.
Voting versus operator “manual selection”
Modern systems usually auto-reject a deviant sensor and present status to the DPO. Operator responsibilities remain:
- Notice the alarm — do not silence and forget.
- Understand remaining tolerance — after one rejection, the next failure is more dangerous.
- Avoid forcing a known-bad sensor online just to clear a red light before a critical task.
- Coordinate repair with ETO/engineers; gyro and MRU faults are maintenance priorities on DP.
- Reflect degraded sensors in ASOG/CAM decisions — critical simultaneous operations may need to stop if sensor diversity falls below the activity’s limits.
Manual selection of a preferred gyro can be available on some systems for maintenance or known intermittent faults. Use it with discipline: selecting the wrong unit during a dual conflict can command thrusters on false heading.
Worked scenarios
Scenario A — classic 2oo3 success
Gyros 1, 2, and 3 online. Gyro 2 jumps 30° due to a fault. Voting rejects Gyro 2; Gyros 1 and 3 continue. Thrusters do not follow the 30° spike. Alarm shows Gyro 2 rejected. DPO calls for investigation but station-keeping remains stable. This is exactly why triple + 2oo3 exists.
Scenario B — dual conflict
Only two gyros fitted or only two healthy. They diverge by 15°. The system alarms “gyro mismatch.” It cannot honestly know which is right. Options may include last good heading freeze, model support for a short time, or operator intervention — vessel-specific. Safe response is to reduce risk, use independent checks (visual transit, PRS track consistency, third portable reference if available per company practice), and avoid aggressive DP work until resolved.
Scenario C — common power failure
Three gyros, one UPS distribution fault kills power to all three. Voting never gets a chance — all inputs die together. Lesson: count independence, not only stickers that say “Gyro 1/2/3.”
Scenario D — Class link
On a Class 2/3 vessel, a single gyro failure should be an equipment fault you manage, not an immediate design-normal loss of position. On a Class 1 vessel with one gyro, the same failure may directly threaten heading control and position-keeping. Class philosophy and sensor architecture travel together.
Sensor voting and PRS voting — same family, different inputs
| Feature | Sensor (e.g. gyro) voting | PRS voting / weighting |
|---|---|---|
| Quantity | Heading, wind, motion | Position (N/E or relative) |
| Typical method | 2oo3 among like sensors | Multi-reference median/weights + quality |
| Goal | Protect control from bad heading/wind/motion | Protect estimate from wild position jumps |
| Independence need | Power/data separation of sensors | Different PRS physics and correction sources |
Do not say sensor voting makes PRS diversity unnecessary. A perfect triple gyro suite with only one flaky DGNSS is still a position-reference risk.
Exam traps
| Trap | Correct framing |
|---|---|
| “Dual gyros can majority-vote the bad unit out” | Dual can detect mismatch; triple enables majority reject |
| “Three gyros on one power supply are fully redundant” | Shared power is a common-mode failure |
| “Rejected gyro means the system is broken and DP must always stop instantly” | Rejection of one wild unit is often protection working; assess remaining sensors and ASOG |
| “Voting replaces Class 2 thruster redundancy” | Voting protects measurements; thrusters still need their own redundancy |
| “Wind sensors never need redundancy” | Wrong wind feed-forward can still disturb thruster demand; designs often duplicate critical environmental sensors |
DPO checklist for sensor integrity
- Know how many gyros/MRUs/wind sensors are online and accepted at handover.
- Treat first rejection as a loss of spare, not a cosmetic event.
- After dual conflict, assume you may not know which is true until proven.
- Verify power and network independence in FMEA awareness — ask which failures kill multiple sensors.
- Link sensor health to consequence analysis and ASOG before critical work.
Bottom line: Critical DP sensors are triplicated so 2-out-of-3 voting can reject a single bad unit. Dual suites cannot choose the correct sensor when they disagree. Redundancy only counts if power and data paths are independent. Sensor voting is a core part of making Class 2/3 single-fault claims real for the measurement chain.
What does 2-out-of-3 (2oo3) voting do when three gyros are online and one reading is wildly different?
Why is a dual (two-sensor) suite limited compared with a triple suite for voting?
Which arrangement best supports real sensor redundancy rather than cosmetic duplication?
A Class 2 vessel rejects one of three gyros after 2oo3 voting. What is the most accurate operational interpretation?