Voting in safety functions: 1oo2, 2oo3 and degraded operation

Read the voter truth table, derive dangerous and spurious benchmarks, and identify which logic remains when a channel is unavailable.

On this page

An architecture label describes a voting rule, not a complete safety claim. This worked comparison starts with binary truth tables, keeps demand and no-demand conditions separate, and then examines two different approved degraded-state possibilities. It shows why removing a channel does not by itself specify the protection that remains.

Define what a vote means

Let each channel output be one for a demand to trip and zero for no trip vote. A kooN voter actuates when at least k of N channels vote to trip. This convention must be explicit: a field signal can be energised or de-energised for safety, and an electrical bit is not automatically the same thing as the logical vote used here.

For the model, the process condition is already classified as genuine demand or no demand. The voter is perfect and instantaneous. Sensors give independent, identically distributed binary outcomes conditional on that condition. Communications, logic hardware and final elements are excluded from the numerical benchmark. These boundaries allow the mathematics to isolate voting without claiming the complete safety function has the same failure probability.

Read the two-channel truth table

The table lists every possible pair of logical votes. For 1oo2, either channel is sufficient; for 2oo2, both must vote. The difference appears in the mixed rows. Agreement alone therefore cannot tell a reviewer which design is safer: the correct decision depends on whether a real demand exists and on the required safety function.

AB1oo22oo2
0000
0110
1010
1111

On a genuine demand, a mixed row means one channel has failed to vote. The 1oo2 voter still actuates, whereas 2oo2 does not. With no demand, the same mixed row represents one false vote: 1oo2 actuates spuriously while 2oo2 does not. The bits have not changed; their safety interpretation changes with the physical condition against which they are judged.

Read the three-channel majority table

A 2oo3 voter requires at least two trip votes. It accepts each combination containing a majority of ones and rejects each combination containing a majority of zeroes. This permits one missing vote on a genuine demand, and rejects one false vote when there is no demand. The statement assumes the voter receives the votes correctly.

ABC2oo3
0000
0010
0100
0111
1000
1011
1101
1111

HSE describes sensor voting as a hardware fault-tolerance measure and includes supporting elements within the safety-related boundary. The majority table is only a logic specification within that boundary. A common sensor input, unavailable power supply, faulty voter or failed final element can defeat the function even when the abstract table is entirely correct.

Derive dangerous failure on a real demand

Let q = 0.02 be each channel’s probability of not voting on a genuine demand. For 1oo2, both must fail, giving q² = 0.0004. For 2oo2, failure occurs if either channel fails: 1 − (1 − q)² = 2q − q² = 0.0396. The probabilities refer to the same stipulated channel population and demand conditions.

For 2oo3, count exactly two failed channels and all three failed channels: 3q²(1 − q) + q³ = 3q² − 2q³ = 0.001184. A 1oo1 reference has dangerous failure probability 0.02. The comparison is a conditional Boolean benchmark, not an average proof-test calculation; it has no assumed test interval, repair duration, diagnostic coverage or failure-rate conversion.

Calculate false actuation under no demand

Now let s = 0.01 be each channel’s probability of a false trip vote at a specified no-demand observation. The 1oo2 false-actuation probability is 1 − (1 − s)² = 0.0199. The 2oo2 value is s² = 0.0001. For 2oo3, the same majority counting gives 3s²(1 − s) + s³ = 0.000298. The 1oo1 reference is 0.01.

These are probabilities at the defined observation, not spurious-trip rates per hour. Turning them into downtime or annual trip counts requires a temporal model, persistence and reset rules, and repair behaviour. Likewise, q and s condition on different physical states; their sum is not required to be unity. They cannot be interchanged simply because both describe erroneous channel outputs.

Original voter comparison. A logical one is a trip vote. A two-channel mixed vote actuates 1oo2 but not 2oo2. With q equal to 0.02 and s equal to 0.01, dangerous and false-actuation probabilities are 0.0004 and 0.0199 for 1oo2; 0.001184 and 0.000298 for 2oo3; 0.0396 and 0.0001 for 2oo2. A lost channel requires an explicitly approved remaining logic.
Independent-channel benchmarks with perfect voting and excluded final elements. Dangerous failure is conditioned on a real demand; false actuation is a no-demand snapshot. The alternative degraded rules are analytical possibilities, not bypass instructions.

Identify the actual degraded logic

Suppose one channel of the normal majority arrangement is unavailable. An approved design may specify a degraded 1oo2 rule over the remaining channels; a different approved design may specify 2oo2. These are alternatives to be established from the safety requirements and validated implementation, not settings to select from this article. Removing the channel name does not resolve the mixed-vote rows.

Under the first alternative, the independent benchmarks are dangerous failure 0.0004 and false actuation 0.0199. Under the second they are 0.0396 and 0.0001. These contrasting results explain why a record saying only “one channel unavailable” is incomplete. The analysis must retain active-channel identities, voting threshold, diagnostic treatment, final action and the conditions under which that state is permitted.

Treat degraded operation as a managed state

The HSE/OMAR inspection guide addresses the management and assessment of protection overrides. That context does not authorise a bypass here. The analyst needs the existing approved degraded-state specification, its risk assessment and evidence that the implemented logic matches it. If these are missing, the remaining architecture is unresolved rather than assumed to be the most convenient label.

A state description also needs entry, duration, restoration and concurrent-unavailability assumptions. The probability of a demand during that state may differ from normal operation, especially when the reason for channel loss also affects the process. State occupancy can weight a risk model only when the state’s conditional demand exposure and protection behaviour are represented consistently. A nominal normal-mode calculation cannot cover these missing facts.

Reintroduce dependencies and the final action

Conditional independence is a benchmark assumption, not a consequence of owning several sensors. A common impulse path, environmental exposure, shared maintenance error or systematic fault can correlate the votes. Under such conditions, calculating q² from a marginal channel probability can substantially understate joint failure. Model explicit shared events or a justified joint distribution instead of applying independence by habit.

The final actuator and logic solver can add failure paths that do not benefit from sensor redundancy. If a shared final element cannot execute the required action, a correct majority vote is insufficient. Retain the sensor, transmission, voter, output and process-response boundaries separately, then combine them with their dependencies. Avoid counting a shared failure once inside channel data and again as a separate event.

Verify the specification with exhaustive cases

For a small binary voter, exhaustive enumeration is straightforward and independently checkable. Generate all input combinations, calculate their probability under the stated condition, apply the truth table and add the probabilities of incorrect outputs. Check that input masses sum to unity. This approach verifies the polynomial calculation without importing it into the test as the expected answer.

Extend validation beyond the static rows when implementing a real specification: stale or invalid signals, timing differences, latching, reset, diagnostics and state transitions can matter. The correct abstract vote can still arrive too late for the process safety time. Those behaviours require their own requirements and tests; this article supplies no field manipulation, tuning sequence or instruction for defeating a channel.

Report two error measures and one precise boundary

HSE frames functional safety around the required function and its lifecycle. Reporting an architecture name without the function, demand assumptions and supporting evidence therefore omits essential context. None of the numerical results certifies a SIL or establishes that a chosen architecture satisfies an installation’s requirements. Random-error arithmetic does not prove systematic capability or lifecycle compliance.

Keep the two truth tables, the dangerous and no-demand benchmarks, the approved degraded-rule reference and the excluded failure paths together. The useful conclusion is conditional: voting changes which combinations matter, and degraded operation changes that logic only as its specification says. A reviewer should be able to reconstruct both the output for each input row and the physical circumstances under which that output is correct.

Sources

  1. HSE — Control systems.
  2. HSE — Functional safety.
  3. HSE / OMAR — Functional Safety Inspection Guide.