Rigid folding

Splitting a sheet buys area, not certainty

A folded deployable with one freedom needs every hinge and its one actuator, and three hundred hinges at 0.999 each open all the way 73 per cent of the time. Split the same hinges among ten separately driven modules and a stuck hinge costs only its own module: the share of the area expected to open rises to 96 per cent, and the chance of at least nine tenths of it rises to 94. The chance of all of it falls, to 67 per cent, because every freedom added is an actuator added. So freedoms, actuators and reliability trade in a definite way: one freedom is the best design only for a mission that is worthless without its whole area, and for any mission that can live with less, several freedoms win by a margin that no improvement in the hinges matches.

Assumes The crease count is a reliability budget and Two drivers and one freedom.

The crease count is a reliability budget priced a deployment that needs every hinge: the hinge reliability to the power of the hinge count, so three hundred hinges at 0.999 each give a 74 per cent chance of opening. It ended with engineering’s usual answer to a series system, which is to stop it being one. A pattern that opens with one crease stuck is a pattern whose reliability is not a product, and whether freedoms bought with actuators beat the single freedom they replace is an arithmetic question with all its terms available.

The terms are three: how many freedoms the sheet has, how many actuators those freedoms need, and how reliable the result is. They trade against each other along a definite curve, and where a design should sit on it depends on something the reliability arithmetic had not yet asked — how much of the deployment the mission can do without.

Freedoms against actuators against reliabilityA deployment of 300 hinges split among one to 100 separately driven modules: the chance the whole area opens, the share of it expected to open, and the chance that a partial requirement is met. More freedoms mean more actuators and a worse chance of everything, and a much better chance of nearly everything.one freedom, or severala stuck hinge or a failed actuator loses its own module and nothing elsemodulesall of it opensshare expectedat least 90%at least 75%173.3%73.3%73.3%73.3%272.6%85.2%72.6%72.6%570.4%93.2%70.4%96.0%1067.0%96.1%94.4%99.4%2060.6%97.5%98.7%100.0%5044.8%98.4%100.0%100.0%10027.1%98.7%100.0%100.0%300 hinges at 0.999 each, split evenly · each module's actuator works 0.99 of the time
Fig. 1 Three hundred hinges working 999 times in a thousand, split among one to a hundred separately driven modules, each with an actuator working 99 times in a hundred: the chance that all of the area opens, the share of it expected to open, and the chance that at least nine tenths and at least three quarters open.

A sheet that fails in parts

The simplest way to give a deployable more than one freedom is to divide it. A solar array, a reflector or a sunshield made of kk panels, each folded with its own pattern and each opened by its own actuator, has kk freedoms, and a stuck hinge in one panel stops that panel and no other.

Call the hinge reliability pp, the actuator reliability aa and the total hinge count nn, split evenly. A single module opens with probability

q=apn/k,q = a \cdot p^{\,n/k},

since it needs its own actuator and its own n/kn/k hinges. The whole area opens only if every module does, with probability

qk=akpn,q^k = a^k \cdot p^{\,n},

and the number of modules that open is binomial: kk trials each succeeding with probability qq.

Two things follow at once. The hinge term pnp^n in the whole-area probability does not depend on kk at all — splitting a sheet does not change how many hinges must all work for all of it to open — while the actuator term aka^k falls with every module added. So for the whole area, more freedoms are strictly worse, and the single-freedom design is right. But the expected share of the area that opens is qq, which rises toward aa as kk grows, because each module needs fewer hinges.

What the table says

With three hundred hinges at 0.999 and actuators at 0.99, one module opens completely 73.3 per cent of the time, and when it fails it fails completely, so the expected share of the area is 73.3 per cent as well.

Ten modules open completely only 67.0 per cent of the time — six points worse, the price of nine extra actuators. But each module needs only thirty hinges, opens 96.1 per cent of the time, and so 96.1 per cent of the area is expected to open. At least nine tenths of it opens 94.4 per cent of the time, against 73.3 for the single module; at least three quarters, 99.4 per cent.

A hundred modules take the whole-area chance down to 27.1 per cent and the expected share up to 98.7. Somewhere between, every partial requirement has its best number of modules, and the table says the number is large: nine tenths of the area is met best with fifty modules or more, and three quarters with twenty.

Where the one freedom wins

How many freedoms a deployment should haveThe chance that a deployment of 300 hinges opens at least a given share of its area, against how many separately driven modules the hinges are split among, for a requirement of the whole area and for two partial requirements. One freedom is best only when nothing less than the whole area will do.00.511.5200.20.40.60.81separately driven modules, log₁₀chance the requirement is metall of the areaat least 90 per centat least 75 per centactuators 0.99 each300 hinges working 0.999 of the time each · a module opens only if its actuator and all its hinges work
Fig. 2 The chance that a deployment of three hundred hinges opens at least a given share of its area, against how many separately driven modules the hinges are split among, from one to a hundred, for the whole area, at least nine tenths, and at least three quarters.

The second figure draws the three requirements as curves. The whole-area curve falls from the first module added; the other two rise steeply, with a saw-tooth where a requirement stops fitting inside one fewer module, and cross above the single-freedom value within a handful of modules.

So the decision reduces to one question about the mission. If the deployment is worthless without its whole area — a starshade that must block a star completely, a sealed enclosure — one freedom is optimal and adding actuators only adds ways to fail. If the deployment degrades gracefully — an array whose power scales with its area, a reflector whose gain falls slowly with its aperture — then several freedoms beat one by a margin no hinge improvement matches: halving every hinge’s chance of failing takes the single module from 73 to 85 per cent, while splitting into ten takes nine-tenths coverage from 73 to 94 without touching the hinges.

The slider on the figure moves the actuator reliability. At an actuator reliability of 0.95 the whole-area curve collapses quickly — ten actuators at 0.95 are only 60 per cent likely to all work — while the partial curves fall much less, because a failed actuator costs only its module. The worse the actuators, the more the choice is decided by the requirement rather than by the hinges.

Better actuators, and the price shrinks

Freedoms against actuators against reliabilityA deployment of 300 hinges split among one to 100 separately driven modules: the chance the whole area opens, the share of it expected to open, and the chance that a partial requirement is met. More freedoms mean more actuators and a worse chance of everything, and a much better chance of nearly everything.one freedom, or severala stuck hinge or a failed actuator loses its own module and nothing elsemodulesall of it opensshare expectedat least 90%at least 75%174.0%74.0%74.0%74.0%273.9%86.0%73.9%73.9%573.7%94.1%73.7%96.9%1073.3%96.9%96.4%99.7%2072.6%98.4%99.6%100.0%5070.5%99.3%100.0%100.0%10067.0%99.6%100.0%100.0%300 hinges at 0.999 each, split evenly · each module's actuator works 0.999 of the time
Fig. 3 The same split with actuators working 999 times in a thousand. The whole-area chance barely falls with added modules — 74.0 per cent at one, 73.3 at ten, 67.0 at a hundred — while the partial requirements rise as before.

With actuators as reliable as the hinges, the price of a freedom nearly vanishes. Ten modules open completely 73.3 per cent of the time against 74.0 for one, and nine-tenths coverage rises to 96.4 per cent. At that actuator quality the single freedom is barely better even for a whole-area mission, and for anything less it is far worse.

That identifies the term that keeps real deployables single-freedom. It is not the hinges: splitting a sheet leaves the hinge term untouched. It is the actuators, and specifically the gap between how reliable a hinge is and how reliable an actuator is. A crease in a folded sheet is a passive joint and an actuator is a device, and devices are less reliable than joints; the one-freedom design is a bet that the actuator is the weak part, which it usually is.

The overdetermination that splitting avoids

Modules that are separate panels with their own actuators never disagree, because each has its own freedom. A continuous sheet given two freedoms and two actuators is different, and two drivers and one freedom is the warning: if the two freedoms are coupled through the sheet, the actuators can fight, and the energy they store depends on how the creases are geared.

That is why the tolerant design is a divided one rather than a sheet with extra freedoms. A continuous pattern with two degrees of freedom could in principle open with a locked crease, since the remaining freedom might still carry the rest; but the locked crease then acts as a stiff actuator holding its angle, and the working actuator fights it through whatever gearing connects them. A panel boundary breaks that coupling, which is its whole function here.

Folding that gets built lists the structures that leave laboratories — solar arrays, reflectors, sunshields — and most of the large ones are already divided: arrays of panels on booms, petals on hubs. The arithmetic suggests the division is doing more than making manufacture convenient. It is converting a series system into a parallel one at the cost of an actuator per part, which is the right trade whenever the parts are worth something on their own.

The crease count is a reliability budgetA deployment needing every hinge to work is the hinge reliability to the power of the count, so a pattern that packs better by folding more finely is spending reliability to do it — and demonstrating the result takes a number of successful tests that grows with the count.what a finer pattern costs in confidenceeach hinge working 0.999 of the time, against a target of 99 per cent for the whole deploymenthingesthe system openseach hinge needssuccesses to show itand the article itself899.2%0.9987442,385cannot be tested2497.6%0.9995817,154cannot be tested6094.2%0.99983317,885cannot be tested12088.7%0.99991635,769cannot be tested30074.1%0.99996689,422cannot be testedr consecutive successes put a 95 per cent lower bound of 0.05^(1⁄r) on a hinge, and a flight article deploys once
Fig. 4 The series arithmetic the modules escape: a deployment’s chance of success at five hinge counts with each hinge working 999 times in a thousand, and the tests needed to demonstrate a 99 per cent system.

The fold count, once the sheet is divided

Division changes the other optimum the reliability budget found. On a single sheet, what a mission gets is compaction times the chance that every hinge works, and multiplying a flat-topped packing curve by a steep exponential moved the best fold count well below the packing optimum — from 88 folds to 54 at a hinge reliability of 0.99.

The best fold count is lower than it looksThe compaction a fold count reaches, and the same figure multiplied by the chance that every one of its hinges works. The second peaks at a lower count than the first, so a pattern designed for compaction alone is folded finer than a one-shot deployment should want.020406080100120140010203040foldspacking, and packing times the chance of itpacks best at 88worth most at 54sheet 10, hinge 0.050.99 a hingethe dashed curve is compaction; the solid one is compaction times the chance that every hinge works
Fig. 5 The undivided case: compaction against fold count, and the same curve multiplied by the chance that every hinge works, on a sheet of ten with hinges of radius 0.05 and a hinge working 99 times in a hundred. The expected compaction peaks at 54 folds where the compaction alone peaks at 88.

A divided sheet’s expected area is apn/ka \cdot p^{\,n/k} rather than pnp^n: the exponential is taken to the power 1/k1/k, which flattens it. So the correction that pulled the best fold count down from the packing optimum shrinks as the sheet is divided, and in the limit of many modules the expected-area optimum returns to the packing optimum itself. A divided deployable can afford to be folded finely, because a fine fold’s extra hinges are spread among modules that fail separately.

That is a second, independent argument for division, and it compounds the first. The divided design reaches more of its area and can use a finer fold to do it, and both follow from the same exponent. The price is still the actuators, now paid twice: once in the chance of the whole area, and once in the compaction the actuators themselves take up in the stowed package, which this arithmetic leaves out.

Every hinge its own freedom

The far end of the division is a sheet in which every hinge is driven separately — a module per crease. That is not an abstraction: paper that folds itself describes sheets whose creases are laid with an active material, so every crease is its own actuator.

At three hundred hinges at 0.999 and an active crease that works 99 times in a hundred, the expected share of the creases that fold is ap=0.989a \cdot p = 0.989, and the chance that all of them fold is 0.99300×0.9993000.0360.99^{300} \times 0.999^{300} \approx 0.036. A self-folding sheet almost never folds completely and almost always folds nearly completely, which is the modular arithmetic taken to its limit and is also a fair summary of how such sheets behave in practice.

What it cannot do is open partially and still be a structure. A crease that fails in a continuous sheet is not a missing panel; it is a crease holding the wrong angle inside a mechanism that needed it, and a gearing reflects stiffness squared is the account of what a stiff disagreement inside a one-freedom sheet costs. So the per-crease limit is where the module model stops describing a sheet: division helps only where the boundary between parts actually decouples them, and a crease does not.

A smaller sheet, and a smaller gain

The advantage depends on how much the hinges are costing. With sixty hinges rather than three hundred, one module opens fully 93.2 per cent of the time; four modules take nine-tenths coverage only to 90.5, below the single module, because at four modules nine tenths still requires all four. At twelve modules nine tenths needs eleven and is met 98.7 per cent of the time.

The shape is general. Splitting helps partial requirements once the modules are numerous enough that losing one leaves the requirement met, and it helps most when the hinge term pnp^n is small — when the sheet is large and finely folded, which is exactly when the reliability budget found a single-freedom design weakest.

Reading a design off the curve

A designer holding the second figure needs two numbers about the mission and one about the hardware, and can read the rest.

The share of area the mission can lose fixes which curve applies. The consequence of not meeting it fixes how high on that curve the design must sit. The actuator reliability fixes where the whole-area curve starts falling. A reflector that loses a tenth of its gain gracefully and must meet that nine times in ten is met by about ten modules; the same reflector required to open completely is met best by one, and the difference between the two designs is not a matter of taste but of which of three curves the mission is on.

What the curve adds to the reliability budget is that the budget was never a single number. A deployment has a reliability for each requirement it might be held to, and the one-freedom design, which maximises one of those numbers, is usually minimising several of the others.

What the model assumes

Failures are independent. A hinge failing in one module says nothing about another, and an actuator failing says nothing about the next. Hinges made in one batch, or modules sharing a harness or a latch, fail together, and every partial-coverage probability here is the optimistic case.

A module that fails contributes nothing. A panel stuck part-open contributes part of its area, which would help the single-freedom design more than the modular one, since its one failure is the whole deployment.

Modules are equal and independent mechanically. A module that fails to open can block its neighbour — a petal stuck across another petal — and the model has no geometry in which that can happen.

The requirement is fixed before deployment. A mission that can reconfigure after a partial failure — pointing a reflector differently, rerouting power — has a requirement that depends on which modules failed, not only on how many, and the binomial count does not see that.

And the actuator is the only cost of a freedom. A real module also carries its own hinge line to its neighbours, its own latch and its own mass, and a design with a hundred modules pays for all of them in compaction, which this arithmetic does not charge.

What the table cannot show

It cannot say what a mission’s requirement is. Whether nine tenths of an array’s area is a success or a failure is a decision about the mission, and the table is useful only once that decision is made.

It does not price compaction. A divided sheet packs differently from a continuous one — the panels fold separately and stack — and whether ten modules pack as small as one sheet with the same total hinge count is a geometric question the crease count prices for continuous patterns only.

It does not follow a failure in time. A module that fails to open at the first attempt may open at the second, after its actuator is cycled or its latch shaken; a single-freedom sheet has the same second chance, and both would move every probability here upward by amounts that depend on why the hinges stuck. The count treats every failure as permanent, which is right for a deployment that has to work at a fixed moment and pessimistic for one that can try again.

And it does not include testing. Each module is a smaller article, so demonstrating its reliability takes fewer tests, but there are more of them; how the testing campaign changes with division is a separate computation.

Still open: choosing a pattern for its tests

The last point is where the arithmetic points next. The crease count is a reliability budget found the tests needed to demonstrate a system reliability growing linearly with the hinge count, so a pattern could be chosen to minimise the tests needed for the compaction it delivers rather than to maximise compaction. That criterion is the number of hinges per layer of compaction, and it is a property of each pattern that can be measured on the printed shelf.

Whether it ranks the patterns the way crease length per layer does — and whether it behaves the same way as a pattern is refined — is not settled by anything here. A criterion that counted hinges would favour patterns whose every crease buys a layer, and those are not obviously the patterns that pack best.

Sideways from here, the modules bear on repeated deployment too. What a second deployment costs found that a structure required to work many times must use blunter hinges and pack worse; a divided structure can replace or retire a worn module, which a continuous sheet cannot, so its fatigue budget is spent module by module rather than all at once. The tube that gets built adds that most flown structures are sheets joined to themselves, whose seams are yet another place where a division either is or is not a decoupling.

The modules also make a claim about the history of deployables. From a shell to a solar array found a twenty-five-year gap between the Miura’s publication and its flight, and attributed it to qualifying a mechanism that must work once. A divided design is easier to qualify in exactly that sense — each part smaller, each failure partial — and whether the deployables that flew soonest were the divided ones is a question for the historical record rather than the arithmetic.

The habit worth carrying is about redundancy. Before adding a spare, ask what the system is worth when part of it fails. If the answer is nothing, a spare only adds a way to fail; if the answer is most of it, dividing the system is worth more than improving any part of it, because division changes the product that multiplies every part’s reliability into a sum that each part contributes to.

What this makes readable

Essays that name this one as a prerequisite.

Named alongside this one

Essays reaching for the same objects. Nobody chose these; they are what the concept index makes visible.

What links here

Every essay whose body links to this one.

The objects this essay names

Each one links to every other essay that touches it.

ActuationDegrees of freedomDeploymentExpected-valueReliabilityTrade-off