Spaceflight

The fragments nobody can see and cannot shield against

A catastrophic collision in low orbit makes about a thousand pieces big enough to track and sixty thousand big enough to destroy a spacecraft. The catalogue is under two per cent of the hazard, the gap is not one better radars will close, and the fragments' lifetimes span a factor of twenty-five within a single event.

Assumes Orbital debris, Atmospheric drag and Collisional cascade.

The first rung of this anchor computed the collision rate from a gas-kinetic argument with no orbits in it, and found the quadratic that overtakes the linear once and never goes back. It treated a collision as an event that happens, at a rate, to a population — the same quadratic-against-linear arithmetic that a cascade of asteroid fragments obeys, with the atmosphere in place of the Poynting–Robertson drag.

This rung asks what one of them makes. The answer has two parts and both of them are about distributions rather than about numbers: a distribution of sizes, which decides how much of the debris anybody can see, and a distribution of shapes, which decides how long any of it stays.

1,236 fragments anybody can see, and 63,397 that can kill. The cumulative fragment size distribution from the standard breakup model, for a catastrophic collision involving 1500 kilograms and for an explosion of the same object, both axes logarithmic. The exponents are −1.71 and −1.60, measured off the drawn curves; they are empirical, fitted to ground tests and to the observed clouds of real events, and they are steep. What follows is the reason a catalogue of tracked objects is not a catalogue of the hazard. Above ten centimetres — the size a ground radar can follow in low orbit — the collision makes about 1,236 pieces. Above one centimetre, which is the size that goes through a spacecraft at ten kilometres a second and cannot be shielded against, it makes 63,397. Above a millimetre, which shielding does stop but which erodes a surface, 3,251,385. The tracked population is under two per cent of the lethal one, and the difference is not a gap in the catalogue that better radars will close — objects of a centimetre at a thousand kilometres are beyond any sensor that has been proposed. An explosion makes fewer large pieces than a collision and a comparable number of small ones, because an explosion divides one object and a collision destroys two.
Fig. 1 The cumulative fragment size distribution from the standard breakup model, for a catastrophic collision involving 1,500 kilograms and for an explosion of the same object. The exponents are −1.71 and −1.60, measured off the drawn curves rather than quoted. Above ten centimetres — what a ground radar can follow in low orbit — the collision makes about 1,200 pieces. Above one centimetre, which goes through a spacecraft at ten kilometres a second and cannot be shielded against, it makes 63,000. The tracked population is under two per cent of the lethal one.

Why the exponent is the whole story

A cumulative distribution with slope −1.71 means that going down a decade in size multiplies the number by ten to the 1.71, which is a factor of fifty-one. Two decades is a factor of two thousand six hundred.

So the population is overwhelmingly small pieces, and the mass is overwhelmingly in the few large ones — because mass goes as the cube of size while number goes as size to the −1.71, and 3 beats 1.71 comfortably. One collision therefore produces an object whose mass is essentially unchanged and whose count has risen by four orders of magnitude, distributed almost entirely into sizes nothing can find.

4,338 fragments anybody can see, and 222,494 that can kill. The cumulative fragment size distribution from the standard breakup model, for a catastrophic collision involving 8000 kilograms and for an explosion of the same object, both axes logarithmic. The exponents are −1.71 and −1.60, measured off the drawn curves; they are empirical, fitted to ground tests and to the observed clouds of real events, and they are steep. What follows is the reason a catalogue of tracked objects is not a catalogue of the hazard. Above ten centimetres — the size a ground radar can follow in low orbit — the collision makes about 4,338 pieces. Above one centimetre, which is the size that goes through a spacecraft at ten kilometres a second and cannot be shielded against, it makes 222,494. Above a millimetre, which shielding does stop but which erodes a surface, 11,410,837. The tracked population is under two per cent of the lethal one, and the difference is not a gap in the catalogue that better radars will close — objects of a centimetre at a thousand kilometres are beyond any sensor that has been proposed. An explosion makes fewer large pieces than a collision and a comparable number of small ones, because an explosion divides one object and a collision destroys two.
Fig. 2 The same model for a collision involving eight tonnes — a spent upper stage struck by a defunct satellite, which is the scenario the mitigation guidelines are written against. Four thousand three hundred trackable pieces and two hundred and twenty thousand lethal ones. The scaling with mass is M to the three-quarters, so five times the mass makes three and a half times the fragments; a collision’s severity is much less than proportional to what was involved in it, and the number of such collisions matters far more than their size.

The distinction between the two curves is worth a sentence. An explosion — a residual propellant tank rupturing, which was the dominant source of debris before deliberate destructions and collisions overtook it — divides one object. A catastrophic collision destroys two, and the energy per unit mass is far higher, so it makes more large fragments. Below a centimetre the two converge, which is why the small-debris environment is dominated by the total number of events rather than by their kind.

It is worth saying where the model comes from, because it is empirical in a way that most of the arithmetic in this collection is not. The standard breakup model is a fit — to ground hypervelocity tests in which representative spacecraft hardware was destroyed and the fragments collected and measured, and to the observed clouds from a handful of real on-orbit events whose trackable fragments were catalogued. The exponents are not derived from a fracture theory. They are what the debris of a smashed satellite looks like, measured, and then assumed to be what the debris of the next one will look like.

That is a reasonable assumption for hardware resembling what was tested and a much weaker one otherwise. Modern spacecraft are lighter, more composite and more densely packed than the aluminium structures the tests used, and there is no observational basis for the model’s behaviour on them. The largest single uncertainty in every long-term debris projection is not the launch rate but this.

The three sizes that matter

There are three thresholds in the first figure and each is a piece of engineering rather than physics.

Ten centimetres. This is what a ground-based radar can detect and track at eight hundred kilometres, well enough to maintain an orbit and predict a conjunction. Objects above it are catalogued, and a satellite operator can be warned and can manoeuvre. The catalogue holds a few tens of thousands of such objects.

One centimetre. This is the size that a Whipple shield cannot stop. A shield works by breaking an impactor into a plasma on a thin outer sheet and spreading the load over the inner wall; the technique works up to about a centimetre and fails above it, and above it the impact is a through-penetration. A one-centimetre aluminium fragment at ten kilometres a second carries the kinetic energy of a small car at motorway speed.

One millimetre. Shielding stops these, and they erode: a window pitted, a radiator degraded, a solar cell shorted. They are the reason spacecraft surfaces returned from orbit are cratered.

The population between one and ten centimetres — lethal, and invisible — is the one the whole subject is about. It is estimated at somewhere near a million objects in low orbit, and the estimate comes from models like the one drawn above rather than from observation. What observation there is comes from returned surfaces, from a handful of dedicated radar campaigns that detect small objects statistically without tracking them, and from the impact record on the International Space Station.

The energy figures are worth writing out because they explain why the middle band cannot be engineered around. Kinetic energy goes as the square of the speed, and orbital collision speeds in low orbit average about ten kilometres a second — thirty times a rifle bullet. A one-gram fragment at that speed carries fifty kilojoules, which is a hand grenade. A one-centimetre aluminium sphere weighs about 1.4 grams. There is no material that stops that in a mass a spacecraft can carry, and the reason a shield works below the threshold at all is that it does not try to stop the fragment: it vaporises it and spreads the momentum over a metre of standoff.

So the response to the middle band is not protection but avoidance, and avoidance requires knowing where the fragment is. That is the sense in which the detection threshold and the shielding threshold being an order of magnitude apart is the central engineering fact of the subject: between one and ten centimetres a spacecraft can neither dodge nor survive.

How long any of it stays

The second distribution is the one that is usually left out, and it changes the picture more than the first.

One breakup, lifetimes spanning a factor of 25. Orbital lifetime against the altitude of a breakup, for fragments of three area-to-mass ratios spanning the range the standard model produces. The fragments of one event do not share a ballistic coefficient: a flat panel of insulation and a solid bolt of the same mass differ by two orders of magnitude in area per unit mass, and the atmospheric drag they feel differs by the same factor. So a collision at 600 kilometres does not produce a cloud with a lifetime; it produces a cloud whose lightest members are gone within 3 months and whose densest are there for 6 years. Across the drawn altitudes the spread within one event reaches a factor of 25, which is comparable with the difference between one altitude and another. Two consequences follow. A debris cloud sorts itself — the high-area fragments decay first, so what remains after a decade is systematically denser and more dangerous per piece than what was made. And an event's altitude, which is the number always quoted, is only half of what decides how long its debris will be a problem.
Fig. 3 Orbital lifetime against the altitude of a breakup, for fragments of three area-to-mass ratios spanning what the standard model produces. The fragments of one event do not share a ballistic coefficient: a sheet of multi-layer insulation and a solid bolt of the same mass differ by two orders of magnitude in area per unit mass. So a collision does not produce a cloud with a lifetime; it produces a cloud whose lightest members are gone within months and whose densest are there for centuries. The spread within one event reaches a factor of twenty-five, which is comparable with the difference between one altitude and another.

Two consequences follow, and the second is the one that matters.

A debris cloud sorts itself. The high-area fragments decay first, so what is left after a decade is systematically denser per piece than what was made. A cloud does not fade uniformly; it hardens.

There is a third consequence which is about the ejection velocities rather than the shapes. Fragments leave a breakup with speeds of tens to hundreds of metres a second, which in orbital terms is a change of a few tens of kilometres in apogee and perigee — so the cloud is not at one altitude. It is a shell spanning perhaps a hundred kilometres either side of the event, and its lowest members sample an atmosphere ten times denser than its highest. That spreads the lifetimes further, and it spreads the hazard across altitudes that were never involved in the collision.

The altitude of an event is only half of what decides its consequences. The number always quoted after a breakup is the altitude, and it is quoted because the lifetime curve is steep in altitude. It is equally steep in area-to-mass, and that quantity is neither quoted nor known for the fragments of any real event.

One breakup, lifetimes spanning a factor of 100. Orbital lifetime against the altitude of a breakup, for fragments of three area-to-mass ratios spanning the range the standard model produces. The fragments of one event do not share a ballistic coefficient: a flat panel of insulation and a solid bolt of the same mass differ by two orders of magnitude in area per unit mass, and the atmospheric drag they feel differs by the same factor. So a collision at 700 kilometres does not produce a cloud with a lifetime; it produces a cloud whose lightest members are gone within 6 months and whose densest are there for 53 years. Across the drawn altitudes the spread within one event reaches a factor of 100, which is comparable with the difference between one altitude and another. Two consequences follow. A debris cloud sorts itself — the high-area fragments decay first, so what remains after a decade is systematically denser and more dangerous per piece than what was made. And an event's altitude, which is the number always quoted, is only half of what decides how long its debris will be a problem.
Fig. 4 The same picture over a wider range of both variables. The spread reaches a factor of a hundred within a single altitude. A fragment of one square metre per kilogram at five hundred kilometres is gone in months; a compact one at eleven hundred outlasts recorded history. Every real breakup produces both, in numbers the model gives and nobody has measured.
A year at 400 km and 2389 years at 900. Orbital lifetime against starting altitude for a circular orbit, integrated from da/dt = −ρav/β with a ballistic coefficient of 200 kg/m² and a piecewise-exponential fit to the 1976 standard atmosphere. Only the density profile is tabulated; the decay is computed. The curve rises by a factor of 1396 between 400 and 900 kilometres — 21 months against 2,389 years — because the density falls by four decades across that span while nothing else in the expression changes much. That single ratio is why an altitude either cleans itself or does not. Below about 600 km a fragment is gone before it can find anything; above 800 it is there for centuries, and the twenty-five-year disposal rule is a statement about which side of this curve an operator is required to leave the vehicle on.
Fig. 5 The underlying decay curve, for a dense fragment with twice the standard ballistic coefficient. Four decades of atmospheric density between four hundred and nine hundred kilometres, and therefore a lifetime rising from about a year to two thousand three hundred. The twenty-five-year disposal guideline is a statement about which side of this curve an operator must leave a vehicle on, and the guideline’s effectiveness depends entirely on the vehicle’s own ballistic coefficient — which is why a disposal requirement stated in years rather than in altitude is the right shape.

Putting it back into the rate

Returning to the first rung’s arithmetic with these two distributions changes what the numbers mean. That calculation set a production rate quadratic in the population against a removal rate linear in it and asked where the two cross; both terms were evaluated on the objects a radar can see, and both are wrong by a different factor for the population that actually ends missions.

A quadratic and a linear, crossing at 220 objects. The two rates that decide whether a shell at 800 km is stable, against how many objects are in it. Production goes as N² — every collision needs two objects, so the number of collisions is proportional to the square of the population, and each one is taken here to make 3000 trackable fragments. Removal goes as N, because drag acts on each object independently and takes 421 years to do it at this altitude. A quadratic and a linear cross exactly once, at 220 objects in this shell, and above that crossing the population grows with nothing launched. The shell presently holds about 2,450, which is 11 times the crossing. Every number on the production side is uncertain by a factor of a few — the fragment yield most of all, and the cross-section is calibrated against an observed collision rate rather than measured — so the position of the crossing carries that uncertainty with it. The shape does not, and the shape is the argument: a quadratic overtakes a linear once and never comes back, the crossing falls as the altitude rises because the lifetime is in the denominator, and what results is a threshold rather than a trend.
Fig. 6 The quadratic production against the linear removal, with a fragment yield of three thousand per collision instead of the standard sixteen hundred. The crossing moves to a lower population, because a more productive collision reaches the runaway sooner. The yield is not a free parameter — it follows from the breakup model in the first figure once a size threshold is chosen — and the threshold is precisely the trackable one, so the whole cascade calculation is conventionally done on the two per cent of fragments anybody can count.

That last observation is the essay’s point restated. The Kessler argument is usually made on the trackable population, because that is the population there are data for. The lethal population is fifty times larger and obeys a different removal law, because its area-to-mass distribution is different — smaller fragments are systematically higher in area per unit mass, so they decay faster, so the small population is more self-cleaning than the large one.

Whether that helps depends on altitude, and it stops helping above about eight hundred kilometres — the altitude above which an orbit that speeds up as it is slowed down has essentially stopped being slowed at all.

There is also a term the gas-kinetic picture leaves out entirely, and it works the other way. The atmosphere’s density at these altitudes is not constant: it rises and falls with the solar cycle by a factor of several, because extreme ultraviolet from the Sun heats and expands the thermosphere. So the removal rate is modulated on an eleven-year period, and the density model it is computed from is wrong by a factor of two at any given moment. A debris projection over fifty years is a projection over five solar cycles whose amplitudes are not predictable.

The population peaks at 825 km, and so does the risk. Tracked objects per 50-kilometre shell against altitude, with the collision rate on a single object computed from each bin as nσv — a gas-kinetic rate, not an orbital calculation. The cross-section is not a satellite's area but an effective one, 7395 square centimetres, fixed by requiring the whole tracked population to produce the one catastrophic collision every 8 years that is observed — most tracked objects are fragments, and two fragments meeting make nothing new. The distribution is not smooth and its shape is history: the peak of 3,010 objects near 825 km is four decades of launches into sun-synchronous orbit plus the debris of two deliberate destructions, and the second rise past 1,300 km is the Soviet-era navigation constellation. At the peak one such object waits 46,409 years between strikes — which sounds safe until it is multiplied by the 3,010 objects sharing that shell, giving one collision every 31 years among them, and by the 23,680 in the whole of low orbit, giving one every 8. The rate on one object is reassuring and the rate on the population is not, and they are the same number.
Fig. 7 The tracked population by altitude, in fifty-kilometre shells. The peak at 825 kilometres is four decades of launches into sun-synchronous orbit plus the debris of two deliberate destructions, and it sits exactly where the atmosphere has stopped removing anything. The shape of this distribution is history rather than physics, which is what makes it a policy problem rather than an astronomical one.

That figure counts objects, and a count is only one of the ways a population can be weighed. Weighting the same fragments by mass, or by the cross-section they present to something moving at ten kilometres a second, gives two pictures that barely overlap — and the difference between them is what decides which debris is worth removing and which merely has to be survived.

Mass at the top, area at the bottom, 7 decades apart. Two moments of a collisional cascade's size distribution, per logarithmic interval of diameter, over 7 decades from a ten-micron grain to a hundred-kilometre parent body. Both axes are logarithmic and the vertical scale is arbitrary; only the slopes carry the argument. A population in which every collision makes fragments that go on to collide reaches a steady state where the same mass flows through every size per unit time, and that fixes the differential number distribution at an index of 3.4. The two consequences pull opposite ways. Mass per decade goes as the diameter to the power 0.6, so it climbs and almost all the mass is in the largest few bodies. Cross-sectional area per decade goes as the diameter to the power -0.4, so it falls, and almost all the area — which is what scatters light, what is detected, and what anything passing through gets hit by — is in the smallest. Over the range drawn the small end carries 631 times the area of the large end and 6·10⁻⁵ times its mass. A disc's brightness therefore measures a population whose mass it says nothing whatever about, and the two numbers are connected only through the index of this line.
Fig. 8 And the same size distribution seen as a mass budget. With a differential slope of 3.4, the mass is concentrated at the top of the range and the cross-sectional area at the bottom, seven decades apart. That separation is why the debris environment has two almost independent problems: a few hundred large derelict objects that hold nearly all the mass and are the only things worth removing, and millions of small fragments that hold nearly all the collision cross-section and cannot be removed at all.

What one event did

The abstractions have a worked example, and it is the reason the numbers above are not hypothetical.

In February 2009 a defunct Russian communications satellite of about nine hundred kilograms struck an operating Iridium spacecraft of about seven hundred, at seven hundred and ninety kilometres, at eleven and a half kilometres a second. The model in the first figures gives, for the sixteen hundred kilograms involved, something over a thousand trackable fragments; the catalogue eventually held about two thousand from the two clouds, which is agreement at the level this model claims. The lethal population it produced is not known and by the model is of order fifty thousand.

Fifteen years later most of those fragments are still in orbit, because seven hundred and ninety kilometres is above the altitude where the atmosphere does anything on that timescale. Two years before, a deliberate destruction of a weather satellite at eight hundred and sixty-five kilometres had produced comparably many. Those two events between them raised the trackable population in low orbit by about a third, and they are the reason the peak in the altitude figure is where it is.

What is actually measured

The catalogue is measured. About forty thousand objects above ten centimetres are tracked by radar and optical sensors, their orbits maintained, and their conjunctions computed daily.

Even the catalogue is less complete than the number suggests. The threshold of ten centimetres is a threshold at eight hundred kilometres; at fifteen hundred it is nearer half a metre, and in geostationary orbit it is a metre or worse. So the catalogue’s completeness is itself a function of altitude, and the altitude distribution in the figures above is a convolution of the real one with a sensitivity nobody publishes as a curve. It is also a function of the object’s shape and material — a flat aluminium panel and a carbon-fibre truss of the same size have radar cross-sections differing by an order of magnitude, and the second is the one modern hardware is made of.

Everything smaller is modelled. The lethal population’s size is an output of exactly the kind of calculation drawn above, run over the known history of launches, explosions and collisions, and calibrated against three thin observational threads: the impact record on returned hardware, which samples millimetre debris at the altitude of the returning vehicle; a small number of radar campaigns that detect centimetre objects as statistical events without cataloguing them; and the observed decay of the catalogued population, which constrains the drag model.

What is not measured is worth listing as plainly as what is. Nobody has counted the centimetre population. Nobody has measured the area-to-mass distribution of the fragments of a real on-orbit collision. Nobody has flown an instrument capable of detecting a millimetre impact and reporting its size and direction, except in the crude sense of counting craters on returned surfaces. And nobody has tested the breakup model against a modern spacecraft, on the ground or in orbit.

The area-to-mass distribution is the least constrained input and it is the one this essay has leaned on hardest. It comes from ground hypervelocity tests on representative hardware, extrapolated to sizes the tests do not reach and to materials that were not tested. Its shape has been revised several times, each revision changing the predicted long-term population by tens of per cent.

The generalisation

The structure worth extracting is that a hazard and a catalogue are different populations whenever the underlying distribution is steep.

The catalogue contains what can be detected; the hazard contains what can do damage; and a distribution with a slope steeper than −1 puts vastly more of the second than of the first below any detection threshold. Improving the sensor moves the threshold and leaves the ratio intact, because the distribution is a power law and a power law has no scale.

The same shape appears throughout this collection. The mass in a collisional cascade is at the top and the area at the bottom, so a survey that finds the mass finds none of the surface. A count with a knee in it is a distribution whose faint end dominates the number and whose bright end dominates the light; a family whose size is a choice grows with every survey for the same reason and with the same ambiguity about how much of the growth is real.

There is a second reading, about what a model is for when the thing it models cannot be observed. Nothing in the small-debris environment is measurable in the way the catalogue is, and nothing will be. The model is therefore not a summary of observations but a substitute for them — and the appropriate response is not to distrust it but to be precise about which of its inputs the conclusion actually rests on. Here the conclusion “the lethal population is fifty times the trackable one” rests almost entirely on one exponent, which is measured, on ground; the conclusion “the environment is stable at eight hundred kilometres” rests on the area-to-mass distribution, which is much weaker.

The corollary is a rule for reading any statement about a debris environment, a small-body population or a faint-galaxy count. Ask what fraction of the quantity being discussed lies below the detection limit, and if the answer is most of it, the number quoted is a model’s output wearing an observation’s clothes.

What follows for the guidelines

The mitigation rules that exist are all statements about the two distributions in this essay, whether or not they are written that way.

The twenty-five-year rule. A vehicle must re-enter within twenty-five years of the end of its mission. That is a statement about the lifetime curve: it puts the disposal orbit below about six hundred kilometres for a typical ballistic coefficient. The rule is stated in years rather than in altitude precisely because the ballistic coefficient varies, and it is being tightened to five years in some jurisdictions — which moves the boundary down by roughly a hundred and fifty kilometres.

Passivation. Residual propellant and pressurant must be vented and batteries discharged at end of life. That addresses the explosion curve in the first figure, which was the dominant debris source until the 2000s and is now a minor one. It is the single most successful piece of debris mitigation ever undertaken, and it is invisible because what it produced was an absence.

Collision avoidance. Manoeuvre when the computed probability exceeds a threshold. That addresses only the trackable population, by construction, and it is therefore a defence against two per cent of the hazard — which is nonetheless the right two per cent, because those are the objects that would make new fragments rather than merely destroy the spacecraft.

Nothing addresses the centimetre band. There is no proposal that does.

Where the ladder goes next

The next rung takes the removal side seriously. Active debris removal — capturing and de-orbiting derelict objects — is the only proposal that addresses the large population, and the arithmetic of which objects to remove is a genuinely interesting optimisation: the right targets are not the most massive or the most numerous but the ones whose product of mass and collision probability is largest — the same kind of weighting an orbital-transfer budget applies to a different quantity — which turns out to select a few tens of specific rocket bodies.

Further rungs on this anchor: conjunction assessment, and why a collision probability of one in ten thousand is the threshold at which an operator manoeuvres; the deliberate destructions and what they cost, measured in fragments still in orbit; the very large constellations now being launched, whose own collision avoidance is automated and whose disposal reliability is the parameter the whole future environment turns on; and the same arithmetic in geostationary orbit, where there is no atmosphere at all and the removal term is exactly zero.

What links here

Essays that link to this one from their own argument.

The objects this essay names

Each one links to every other essay that touches it.

Area-to-mass ratioBallistic coefficientBreakup modelConjunction assessmentHypervelocity impactKessler syndromeOrbital debrisOrbital lifetimeSpace surveillanceWhipple shield