Spaceflight

A fuel gauge that is worst when it is needed

A spacecraft's tank has no float and no dial. The propellant left is estimated by adding up every burn or by reading the pressure and temperature of the gas above the liquid, and both methods' errors grow with the propellant used. Relative to what remains, the error doubles every time what remains halves — so a geostationary satellite has to hold back months of station-keeping as a margin against a gauge that cannot see the last few kilograms.

Assumes Station-keeping, Rocket equation and Photon noise.

A geostationary satellite pays for its orbit every year, and it stops paying when the propellant runs out. It does not simply stop, because a dead satellite left in the geostationary ring drifts into one of two stable longitudes and becomes a hazard to everything still working there. The last thing it must do is raise itself a few hundred kilometres into a graveyard orbit, which costs about eleven metres per second. So the operator has to know, some time before the tank is empty, that at least eleven metres per second of propellant is still in it.

That turns out to be one of the hardest measurements a spacecraft makes. There is no float in a tank that is weightless, and the liquid clings to walls and baffles and moves wherever the last manoeuvre left it. What is left is estimated indirectly, and the estimate’s error has a structure that makes it worst at exactly the moment it matters.

A gauge good to 7 per cent with a tenth of the load left, and to 23 per cent with three hundredths. The uncertainty in the propellant remaining in a spacecraft tank, as a percentage of what remains, against the fraction of the 450-kilogram load still in the tank, on a logarithmic uncertainty axis with the tank emptying to the right. Bookkeeping — summing every thruster firing through a flow-rate model — carries an error common to all burns of 2 per cent of the mass used, plus an independent 5 per cent per burn that averages down over 2000 firings; its absolute error grows with the mass used. Gauging by pressure and temperature infers the empty volume of the tank from the gas law applied to a known mass of pressurant, with a combined 0.66 per cent uncertainty in n R T / P and a 0.2 per cent uncertainty in the tank's volume; its absolute error grows as the gas fills the tank. The two methods are independent and are combined by inverse variance. With a tenth of the load left the combined estimate is uncertain by 2.9 kg, 7 per cent of what remains; with three per cent left, by 3.1 kg, 23 per cent. Near empty the absolute error barely changes, so halving what is left doubles the relative error — the gauge is at its worst exactly when the last manoeuvre has to be planned from it.
Fig. 1 The uncertainty in the propellant remaining, as a percentage of what remains, against the fraction of a 450 kg load still in the tank, as the tank empties to the right. Bookkeeping carries 2 per cent of the mass used as a common error across all burns plus 5 per cent per burn averaged over 2000 firings; pressure–temperature gauging carries 0.66 per cent in the gas law and 0.2 per cent in the tank’s volume. Combined, the estimate is uncertain by 2.9 kg — 7 per cent of what remains — with a tenth of the load left, and by 3.1 kg — 23 per cent — with three per cent left.

Adding up the burns

The first method is bookkeeping. Every thruster firing is logged — its duration, the valve’s opening, the tank pressure at the time — and a model of the thruster’s flow rate converts each firing into a mass of propellant used. Subtract the sum from what was loaded and the remainder is what is left.

The method’s error has two parts, and they behave very differently. Each individual firing’s mass is uncertain because the flow depends on temperature, on how the valve opens in pulses of milliseconds, and on how the thruster has aged; those errors are different from burn to burn and average down over thousands of firings. But the flow model itself can be wrong by a fraction that applies to every burn — a calibration made on the ground at a different temperature, say — and that error does not average. After using a mass U, the bookkeeping uncertainty is

σbook2=(εsysU)2+(εrandU)2N\sigma_{\rm book}^2 = (\varepsilon_{\rm sys}\,U)^2 + \frac{(\varepsilon_{\rm rand}\,U)^2}{N}

For thousands of burns the systematic term wins. A two-per-cent error in the flow model applied to 440 kilograms of propellant used is almost nine kilograms of uncertainty — more than the eleven metres per second of the disposal manoeuvre needs — and it is largest when the tank is nearly empty, because that is when the most has been used.

This is the same shape as the counting error that stops averaging at a systematic floor: the random part of an error shrinks with repetition, the common part does not, and after enough repetitions the common part is all there is.

Reading the gas above the liquid

The second method reads the tank’s physical state. Most spacecraft tanks hold the liquid propellant together with a pressurising gas, usually helium, whose mass was loaded before launch and is known. The gas occupies whatever volume the liquid does not. Measure its pressure and temperature, apply the ideal gas law to the known amount of helium, and the gas volume follows; subtract it from the tank’s volume and multiply by the liquid’s density to get the propellant mass:

m=ρ(VtanknRTP)m = \rho\left(V_{\rm tank} - \frac{nRT}{P}\right)

The fractional error of nRT/PnRT/P comes from the pressure transducer, the temperature sensor — a kelvin at three hundred is a third of a per cent — and the knowledge of how much helium was loaded. That fractional error multiplies the gas volume, which grows as the propellant is used. Near empty the gas fills nearly the whole tank, so the error in the propellant mass approaches the density times the tank volume times the fractional error: a fixed number of kilograms, while the propellant it is being compared with shrinks towards zero.

Both methods therefore arrive at the same pathology from different directions. Bookkeeping’s absolute error grows with the propellant used; gauging’s grows with the gas volume, which is the same thing. Neither error shrinks as the tank empties, and the quantity they are uncertain about does.

Combining the two

The two errors are independent — one is a flow model, the other a gas law — so the best estimate weights each by the inverse of its variance, and the combined uncertainty is smaller than either:

1σ2=1σbook2+1σpvt2\frac{1}{\sigma^2} = \frac{1}{\sigma_{\rm book}^2} + \frac{1}{\sigma_{\rm pvt}^2}

In the first figure the pressure-temperature method is the better of the two near empty, and the combination is only slightly better than it. That ranking depends entirely on the instruments.

A gauge good to 3 per cent with a tenth of the load left, and to 9 per cent with three hundredths. The uncertainty in the propellant remaining in a spacecraft tank, as a percentage of what remains, against the fraction of the 450-kilogram load still in the tank, on a logarithmic uncertainty axis with the tank emptying to the right. Bookkeeping — summing every thruster firing through a flow-rate model — carries an error common to all burns of 2 per cent of the mass used, plus an independent 5 per cent per burn that averages down over 2000 firings; its absolute error grows with the mass used. Gauging by pressure and temperature infers the empty volume of the tank from the gas law applied to a known mass of pressurant, with a combined 0.24 per cent uncertainty in n R T / P and a 0.1 per cent uncertainty in the tank's volume; its absolute error grows as the gas fills the tank. The two methods are independent and are combined by inverse variance. With a tenth of the load left the combined estimate is uncertain by 1.2 kg, 3 per cent of what remains; with three per cent left, by 1.3 kg, 9 per cent. Near empty the absolute error barely changes, so halving what is left doubles the relative error — the gauge is at its worst exactly when the last manoeuvre has to be planned from it.
Fig. 2 The same tank with better instruments: pressure and temperature to 0.1 per cent, the helium load to 0.2 per cent and the tank volume to 0.1 per cent, a combined 0.24 per cent in the gas law. Bookkeeping is unchanged. With a tenth of the load left the combined uncertainty is 1.2 kg, 3 per cent of what remains; with three per cent left, 1.3 kg, 9 per cent. The curve is lower and has exactly the same shape, because the divergence as the tank empties is a property of what is being divided by, not of the instruments.

Better instruments lower the curve and do not change its shape. The relative uncertainty still doubles every time the remainder halves, because the absolute error is still nearly constant near empty. No improvement in a gauge of this kind removes the divergence; it only moves the point at which the uncertainty becomes as large as what is left.

A gauge good to 4 per cent with a tenth of the load left, and to 14 per cent with three hundredths. The uncertainty in the propellant remaining in a spacecraft tank, as a percentage of what remains, against the fraction of the 450-kilogram load still in the tank, on a logarithmic uncertainty axis with the tank emptying to the right. Bookkeeping — summing every thruster firing through a flow-rate model — carries an error common to all burns of 1 per cent of the mass used, plus an independent 5 per cent per burn that averages down over 2000 firings; its absolute error grows with the mass used. Gauging by pressure and temperature infers the empty volume of the tank from the gas law applied to a known mass of pressurant, with a combined 0.66 per cent uncertainty in n R T / P and a 0.2 per cent uncertainty in the tank's volume; its absolute error grows as the gas fills the tank. The two methods are independent and are combined by inverse variance. With a tenth of the load left the combined estimate is uncertain by 1.7 kg, 4 per cent of what remains; with three per cent left, by 1.9 kg, 14 per cent. Near empty the absolute error barely changes, so halving what is left doubles the relative error — the gauge is at its worst exactly when the last manoeuvre has to be planned from it.
Fig. 3 Bookkeeping with a flow model four times better, a 0.5 per cent systematic error, and the original pressure–temperature instruments. With a tenth of the load left the combined uncertainty is 4 per cent of what remains, and with three hundredths 14 per cent. Improving the bookkeeping helps more than it did in the other case, because here it becomes competitive with the gas-law method near empty and the combination gains from having two estimates of similar quality.

What the uncertainty costs

The operator’s problem is a decision under that uncertainty. The disposal manoeuvre needs a fixed amount of propellant. If the satellite keeps station until the gauge reads exactly that amount and the gauge is optimistic, the satellite dies in the ring. So a margin is held back: the operator stops station-keeping when the gauge reads the disposal amount plus k standard deviations, chosen so that the chance of arriving at the graveyard short is acceptably small.

Every kilogram of that margin is propellant that could have kept the satellite in its slot, and the rocket equation converts it into time.

Holding three standard deviations of margin costs 4.1 months of a working satellite. The station-keeping time given up at the end of a geostationary mission by holding back a propellant margin of k standard deviations of the gauge's uncertainty, against k, for a 1500-kilogram satellite with an effective specific impulse of 290 s spending 52 m/s a year on station-keeping — 2.31 kg of propellant a month. The disposal raise needs 11 m/s, 5.8 kg. At the moment that is all that should remain, the gauge's uncertainty is 8.9 kg by bookkeeping alone, 3.4 kg by pressure and temperature alone, 3.2 kg by both combined. The margin is k times that, and every kilogram of it is propellant that would otherwise have kept the satellite in its slot: at three standard deviations the combined gauge costs 4.1 months and bookkeeping alone 11.6. The cost is linear in k and in the gauge's error, so improving the gauge by half returns half the lost months — which for a satellite earning revenue every month is the commercial case for better gauging. What k to choose is not an engineering result; it is the probability of failing to reach the graveyard that an operator, or a licensing authority, is willing to accept.
Fig. 4 The station-keeping time given up by holding a margin of k standard deviations, for a 1500 kg satellite with a specific impulse of 290 s spending 52 m/s a year — 2.31 kg of propellant a month. The disposal raise needs 11 m/s, 5.8 kg. When that is all that should remain, the gauge is uncertain by 8.9 kg by bookkeeping alone, 3.4 kg by pressure and temperature alone, and 3.2 kg combined. At three standard deviations the combined gauge costs 4.1 months of mission and bookkeeping alone 11.6.

The numbers are uncomfortable. With the modest instruments of the first figure, a three-sigma margin costs four months of a satellite that might have earned revenue every day of them. With bookkeeping alone, nearly a year. The cost is linear in the margin and linear in the gauge’s error, so every halving of the gauge’s error returns half the lost time — which is a straightforward commercial argument for better gauging and explains why operators spend effort on it.

Holding three standard deviations of margin costs 1.7 months of a working satellite. The station-keeping time given up at the end of a geostationary mission by holding back a propellant margin of k standard deviations of the gauge's uncertainty, against k, for a 1500-kilogram satellite with an effective specific impulse of 290 s spending 52 m/s a year on station-keeping — 2.31 kg of propellant a month. The disposal raise needs 11 m/s, 5.8 kg. At the moment that is all that should remain, the gauge's uncertainty is 8.9 kg by bookkeeping alone, 1.3 kg by pressure and temperature alone, 1.3 kg by both combined. The margin is k times that, and every kilogram of it is propellant that would otherwise have kept the satellite in its slot: at three standard deviations the combined gauge costs 1.7 months and bookkeeping alone 11.6. The cost is linear in k and in the gauge's error, so improving the gauge by half returns half the lost months — which for a satellite earning revenue every month is the commercial case for better gauging. What k to choose is not an engineering result; it is the probability of failing to reach the graveyard that an operator, or a licensing authority, is willing to accept.
Fig. 5 The same satellite with the better pressure–temperature instruments. The gauge’s combined uncertainty at the end of life falls to 1.3 kg, and a three-sigma margin costs 1.7 months instead of 4.1. Bookkeeping alone is unchanged at 11.6 months. A gauge three times better at the end returns more than two months of station-keeping, for a sensor that costs a small fraction of that revenue.

The choice of k is not an engineering result. It is a statement about acceptable risk — of failing to reach the graveyard and leaving a dead satellite in the ring — and it is set by operators, insurers and increasingly by licensing authorities that require a stated probability of successful disposal. A requirement of 90 per cent success corresponds to a small k and a short margin; a requirement of 99.9 per cent to a large one. The same gauge therefore costs a different number of months under a different rule.

Other ways to look inside

Operators have developed methods that read the tank’s contents more directly, each attacking the near-constant absolute error in a different way.

Thermal gauging heats the tank by a known amount and measures how fast its temperature rises. The heat capacity of the liquid is much larger than that of the gas, so the rate of warming measures the liquid mass; the method’s error is set by the thermal model of the tank and its surroundings, and unlike the gas law it does not get worse as the gas volume grows. Its uncertainty is typically a fraction of a per cent of the full load, which near empty is still large compared with what remains, but it is independent of the other two methods and improves the combination.

A second approach watches for the moment the tank is actually running out. As the liquid supply falters, pressure fluctuations appear in the feed lines and thrust becomes irregular. That is a direct detection, but it arrives too late to plan a disposal around; it confirms the end rather than predicting it. In practice operators combine all available estimates in a running model of the tank updated after every manoeuvre, and plan the end-of-life sequence months in advance with a margin that is itself reviewed as the estimates converge.

Propellant that is there and cannot be used

A gauge that read the tank perfectly would still not say how much propellant can be burned. Some of what is loaded is never available. It wets the tank walls and the mesh screens that hold liquid over the outlet in weightlessness, it fills the lines between the tank and the thrusters, and in a bipropellant system one of the two liquids always runs out first, stranding whatever remains of the other. These residuals are typically one or two per cent of the load — for a 450-kilogram load, several kilograms, comparable with the whole disposal requirement.

The mixture-ratio problem is the sharpest of these, because it is itself a gauging problem. A bipropellant engine burns fuel and oxidiser in a fixed ratio, and the two tanks are loaded in that ratio with a small excess of one. If the actual consumption has run slightly rich or lean over fifteen years — a fraction of a per cent is enough — one tank empties while the other still holds kilograms. The operator must gauge both tanks and plan the end-of-life sequence around whichever will run out first, and the uncertainty in the ratio adds to the uncertainty in each.

The electric version of the problem

Satellites that keep station with electric thrusters store xenon rather than liquid propellant, and xenon is kept above its critical point, where there is no liquid and no gas above it — just a dense fluid filling the tank. There is no ullage to read. The mass follows from the fluid’s density, which follows from its pressure and temperature through an equation of state that is strongly non-ideal near the critical point, where a small error in temperature is a large error in density.

The divergence remains in a different form. An electric satellite uses propellant at a rate of a few kilograms a year, because its exhaust is ten times faster, so a gauge error of a kilogram is months of station-keeping rather than weeks. The tanks are smaller and the gauge’s fractional error is often larger, and the engine chosen for its efficiency turns every kilogram of uncertainty into more mission time than a chemical system would. Operators of such satellites have the same margin decision to make with the months scaled up.

Why the leftover has to be burned away

The margin has a second life after the disposal manoeuvre, and it is not a benign one. Once the satellite reaches the graveyard, whatever propellant remains — the margin that turned out not to be needed, plus the residuals — becomes a hazard of its own. Stored propellant under pressure, warmed and cooled by the Sun for decades, can rupture a tank; hypergolic propellants that leak and meet can ignite. A satellite that breaks up in the graveyard sends fragments down through the ring it was moved to protect, and fragments too small to track are exactly the kind that cannot be avoided.

So the final operations after the raise are passivation: burning the thrusters until the tanks are as empty as they can be made, venting the pressurant, and discharging the batteries. That burn to depletion is, incidentally, the only direct measurement of how much propellant was left — made at the moment it can no longer change any decision. Operators who have compared the propellant actually burned during passivation with their final gauge estimates have a record of how good their gauging was, and that record is how the next satellite’s margin is chosen. The margin that was held back is thus spent twice: once in the months of mission it cost, and again in the burn that proves how much of it was needed.

When a second spacecraft changes the arithmetic

In 2020 a servicing vehicle docked with a geostationary communications satellite that had exhausted its propellant, took over its station-keeping with its own thrusters, and extended its working life by five years before returning it to a graveyard orbit and moving on. The docking was a rendezvous in a rotating frame with a target that had not been designed to be caught.

That mission changes the gauging calculation at its root. A satellite that can be serviced, or that can be moved to a graveyard by another vehicle if it fails to move itself, need not hold the whole disposal reserve as its own margin; the probability of leaving a dead satellite in the ring depends on the availability of a rescue as well as on the gauge. Whether regulators accept that argument, and whether operators design satellites to be caught, will decide how much of the months lost to margins can be recovered.

Low orbit, where the air does the disposal

A satellite in low orbit has a different end. The atmosphere removes what stops manoeuvring, so disposal can mean simply lowering the perigee enough that drag brings the satellite down within a set time — historically twenty-five years, and more recently five for new licences in some jurisdictions. The propellant needed is again a fixed Δv, the margin question is identical, and the months lost are fewer only because a low-orbit satellite’s station-keeping budget per month is usually smaller. For large constellations the gauge’s error matters in a different way: a margin of a few per cent held back on thousands of satellites is a fleet-wide decision about how many satellites to replace each year.

The same shape elsewhere

A spacecraft at an unstable Lagrange point pays for station-keeping in proportion to how well its velocity is known, and a geostationary satellite pays for its disposal margin in proportion to how well its propellant is known. In both cases a navigation-like uncertainty becomes a propellant cost, and the propellant cost becomes mission time through the exponential that decides what can be flown.

The divergence itself is general. Any quantity estimated as a large known total minus a large measured subtraction has an absolute error set by the subtraction and a relative error set by the remainder, and as the remainder shrinks the relative error grows without bound. The same structure makes it hard to measure a small difference between two large numbers anywhere — a small parallax as the difference between two positions, a small mass as the difference between two weighings — and the remedy is always the same: measure the small quantity directly rather than as a difference, which for a tank means a method that responds to the liquid rather than to what surrounds it.

What the model leaves out

The error model treats each method’s fractional uncertainties as constants, when in practice they change with the tank’s temperature history, with the helium slowly dissolving into some propellants, and with the liquid’s position in the tank. It treats the two methods as fully independent, which they are not quite, since both depend on the tank volume and on the propellant’s density. And it assumes Gaussian errors, which matters for the choice of k: the tails of a real gauge’s error distribution are set by rare events, such as a sensor offset that develops late in life, which a Gaussian margin does not protect against.

Where the fuel goes, and it is not where a satellite points. Left, the orbit pole of a geostationary satellite, in degrees from the Earth's. The Sun and the Moon between them carry it round a circle of radius 7.4° in 53 years, and a satellite launched into the equatorial plane starts on the rim of that circle rather than at its centre — so its inclination climbs from zero at 0.88° a year, reaches 14.8° after 27 years, and comes back. Right, what holding it costs. A plane change of 0.88° at 3.07 km/s is 47.1 m/s a year; holding the longitude against the equatorial bulge, computed from the same resonant term that makes the longitude a pendulum, is 1.8 m/s a year. North–south is 96% of the budget, and a satellite that gives up on it does not fail — it starts tracing a figure of eight on the sky 1.8° tall in the first year, which a fixed dish cannot follow and a steerable one can. Retiring at the end of the propellant is therefore a choice about which service ends first.
Fig. 6 Where the monthly propellant goes. The Sun and Moon carry a geostationary orbit’s pole round a circle of radius 7.4° in 53 years, so an equatorial satellite’s inclination climbs at 0.88° a year, and holding it costs 47.1 m/s a year against 1.8 m/s for the longitude. North–south control is 96 per cent of the budget, which is why the rate at which a satellite spends its propellant — the divisor that turns a margin in kilograms into months — is set by a lunisolar torque rather than by anything about the satellite.

The reserve calculation uses a fixed station-keeping rate, when in reality the north–south budget varies over the Moon’s 18.6-year nodal cycle and operators often stop north–south control before the end, letting the inclination grow to save propellant. That changes the conversion from kilograms to months, and it is one of the few decisions that can buy back some of the margin’s cost.

Still open: how high the graveyard has to be

The disposal Δv in all of this was taken as eleven metres per second, the cost of raising a geostationary satellite about three hundred kilometres. That height is not arbitrary. It is written into international guidelines as a formula — 235 kilometres plus a thousand times the product of the satellite’s reflectivity and its area-to-mass ratio — and each term is a separate piece of physics: a protected zone, a lunisolar oscillation, and the yearly swing that sunlight drives in a high orbit’s eccentricity. Where the coefficient of a thousand comes from, and how close to the physics it is, decides how much propellant every geostationary satellite must hold in reserve.

About the same objects

Not linked from either essay — found by the objects both name.

The objects this essay names

Each one links to every other essay that touches it.

BookkeepingΔvEnd of lifeGraveyard orbitIdeal gas lawInverse variance weightingPropellant gaugingRocket equationStation-keepingSystematic errorUllage