Contents

Course 15 · Advanced

Powered descent guidance

Solving for a burn that arrives at zero velocity and zero altitude at once, with an engine that cannot throttle to nothing.

A booster falls towards a landing pad at 145 m/s. A lunar lander, its orbit spent, drops towards the surface with nothing under it but the engine. Each has to reach the ground at one chosen point, upright, moving no faster than a walking pace, with as little propellant spent as possible — and each has an engine whose thrust is bounded twice: it cannot exceed a maximum, and it cannot go below a minimum without going out.

Stated precisely: given the vehicle's position , velocity and mass , find a thrust history with , pointing within some angle of vertical, such that at some final time — itself unknown — the position is the target and the velocity is zero, and is as large as possible.

Three things make it hard. It is a two-point boundary-value problem with inequality constraints on the control, and a free final time. Every second of it costs propellant, because an engine holding a vehicle up against gravity is spending velocity it never keeps. And the lower bound on thrust, which sounds like a detail, is what turns a manoeuvre into a knife-edge: an engine that cannot throttle below the vehicle's weight cannot hover, so the vehicle cannot pause, check and correct. It has to get everything right on the way down.

Gravity is the price of time

Start in one dimension: a vehicle falling vertically, with speed measured downwards, in a uniform gravity , and a thrust acceleration when the engine is lit. Then . Integrate from the moment the descent begins, at speed , to touchdown at speed zero, a total time later:

The velocity the engine has to produce is the speed the vehicle started with, plus for every second the descent takes. The second term is the gravity loss, and it is the whole of the cost that can be controlled. So the cheapest descent is the fastest one: fall with the engine off for as long as possible, then brake as hard as possible, as late as possible. That is the suicide burn, or hoverslam — coast, then full thrust, timed so the speed reaches zero at the ground.

This is the answer optimal-control theory gives too. The problem is linear in the thrust magnitude, so Pontryagin's minimum principle makes the optimal thrust sit on one of its bounds at every instant, switching between them. In one dimension, with nothing to aim at, the switch happens once: off, then full. Drag changes the argument only by adding a term that helps.

The ignition altitude

With a constant thrust acceleration , a vehicle falling at stops in the distance . It reaches the ignition altitude at a speed that itself depends on : falling freely from height at speed , . Setting the stopping distance equal to ,

The result has a clean reading: the engine does work per kilogram over the braking distance, and that work has to equal the whole mechanical energy per kilogram the vehicle had at the start. The burn then lasts . Burning propellant makes grow as the burn goes on, so the true ignition point is a little lower; for a short burn the correction is a few per cent.

Take Odyssey's lander on the Moon, as the simulator flies it: 11.3 t, three Vesta engines of 90 kN each, m/s². Let it fall from 2,000 m at 40 m/s. Then m/s², and

It reaches that height at 86.8 m/s and brakes for 3.9 s. The whole descent takes 32.8 s, so m/s, of which 53 m/s is gravity loss.

The knife-edge

Now light the engine at the wrong height. At full throttle, the stopping distance is fixed, so an error in the ignition altitude becomes the same error in the height at which the vehicle comes to rest. Lit too early, it stops above the ground, and — cut — falls the rest and lands at . Lit too late, it reaches the ground still moving at . For a touchdown no harder than 3 m/s, the tolerances are

On the Moon that is 2.8 m early and 0.2 m late: three metres, which at 87 m/s the lander covers in 35 ms. On Earth, where the Hopper falls at 145 m/s with an engine giving it about 40 m/s² net, it is 0.46 m early and 0.11 m late: 4 ms. A flight program called fifty times a second sees the world every 20 ms. No program can time an open-loop ignition that finely, and the engine could not honour it if one did: a real engine has a dead time between the command and the first thrust, then a spool-up.

What the throttle buys

The escape is to keep the burn closed-loop. Once lit, command the deceleration that would stop the vehicle exactly at the ground from where it is now,

with a small touchdown speed, and throttle to it — clamped, necessarily, to what the engine can give. Lit at any height between the one where full throttle only just stops it and the one where the minimum throttle only just stops it, there is a throttle setting that arrives, and the law finds it. The ignition point becomes an ignition window. Its top is the same energy formula with the minimum thrust acceleration:

For the three-engine lander, m/s² and m. The window runs from 169 m to about 1,400 m.

That top edge exists only because . Three Vesta engines at their 12 % floor push 32 kN against an 18 kN lander: the engine at its gentlest still decelerates the vehicle. Lit above the window, it stops in mid-air and cannot stay there. The program's only options are to cut the engine and fall again, spending an ignition, or to keep burning and climb. On one engine the floor is 10.8 kN, below the weight; that lander can hover, its window has no top, and lighting early only costs time — and time, from the first equation, is propellant.

Figure · the landing burn

VEHICLE
BURN
700 m
050010001500020406080ALTITUDE · mDESCENT SPEED · m/sFULL THROTTLEMINIMUM THROTTLE00.505101520THROTTLESECONDS SINCE IGNITIONFLOOR 12%HOVER 7%
OUTCOME
Lands at 1.5 m/s
WINDOW
166–1,391 m
SPEED AT IGNITION
76 m/s
BURN Δv
104 m/s
PROPELLANT
322 kg
FLOOR THRUST / WEIGHT
1.77
Altitude against descent speed. The vehicle falls from the top, engine off (ink), and lights at the altitude you choose (orange). Grey dashes: the full-throttle and minimum-throttle stopping curves, from the ignition mass; the shaded band between them is the ignition window. A vehicle whose engine cannot throttle below its weight has an upper edge to that window; one that can hover does not. Below: the throttle the burn flew, against the engine's floor and the throttle that would hover. No air. The engine lights instantly here; in the simulator it does not.

Try the three cases in turn. On three engines, full throttle, light at 169 m and the lander stops within a couple of metres of the ground; at 186 m it stops 20 m up and, cut, hits at 8 m/s; at 156 m it hits at 23 m/s. Switch to throttle-to-stop and the same 186 m lands softly, as does anything up to 1,360 m; above about 1,390 m the lander stops high even at its floor. On one engine the window has no top, and the readout shows the price instead: 99 m/s from the latest ignition, 195 m/s from the top of the plot. The Hopper is the Earth version of the first case: a floor thrust of 1.75 times its weight, and a window from about 250 m to 1,080 m. There the throttle law gives up a few metres of the window's bottom edge, because it spreads the braking evenly while the drag that helps most is at the start.

The narrowing is the real knife-edge. At any instant of the burn, the heights at which the vehicle could come to rest span from to . As falls both terms shrink, and at touchdown the span is a single point. The last error the guidance can correct is the one it sees before the speed runs out, and the last command it can give is the engine cut, timed against the thrust's tail-off.

Descending in three dimensions

A real descent starts with most of its speed horizontal. The Apollo lunar module began its powered descent about 15 km up, moving at about 1.7 km/s; a booster falls through the last kilometres with its horizontal speed nearly gone but not quite. The vehicle has to kill the horizontal speed too, and arrive over a particular spot.

The gravity turn, run backwards

The simplest law points the thrust straight against the velocity. With the flight-path angle measured below the horizontal, flat ground and constant ,

Divide one by the other, and take the thrust-to-weight ratio as constant:

As the path steepens towards vertical, grows like , so falls like . For any the speed runs out exactly as the path turns vertical: the horizontal and vertical components vanish together, and the vehicle arrives upright without being told to. That is why the final burn of every propulsive landing is flown close to retrograde. But the gravity turn has no aim. It decides where the speed runs out; the only choice left to the program is when to light, and one number cannot place both a height and a downrange position.

Polynomial guidance

Apollo's answer was to choose the trajectory, not the attitude. Pick a time to go and a target — a position , velocity and acceleration to arrive with — and suppose the position is a polynomial in the time from now,

Five vector conditions fix five vector coefficients: and are the vehicle's position and velocity now, and , and the targets. Writing , and , the three target conditions become the linear system

in , and , whose solution gives . The acceleration to command now is :

and the thrust acceleration is that less gravity, . The law is explicit: no stored trajectory, only the present state and the target, re-evaluated every cycle as counts down, so an error at one instant is folded into the next command. Klumpp's guidance for the Apollo lunar module was built on this quartic, flying a braking phase to a "high gate" and an approach phase to a "low gate" a few hundred metres above the site, and fixing each pass from one extra target, the downrange jerk. From low gate the commander flew the last minute or two by hand, adjusting the rate of descent — possible because the descent engine could throttle deep and the lander could hover.

Drop the acceleration target, ask instead for the least , and the same calculus gives the energy-optimal law. Its acceleration is linear in time, and at each instant

where the zero-effort miss and zero-effort velocity error are how far off the vehicle would arrive, and how fast, if the engine did nothing more.

What a formula does not know

Neither law knows that the engine has a ceiling and a floor, or that a lander cannot thrust towards the ground. The commanded acceleration is whatever the polynomial needs, and the choice of decides whether that is something the engine can deliver.

Take a lander on one Vesta engine, 1.5 km up and 3 km uprange, moving towards the pad at 80 m/s and descending at 25 m/s, and aim it to arrive at 1 m/s downward in 90 s. The first command is

so the thrust acceleration is m/s², 1.44 m/s² in magnitude: 16.3 kN on the 11.3 t lander, 18 % of full thrust and comfortably above the 12 % floor.

Figure · polynomial guidance

90 s
3,000 m
01000-6000-4000-20000ALTITUDE · mDOWNRANGE · mPAD00.511.5020406080THRUST / FULLSECONDSFULLFLOOR 12%
OUTCOME
On the pad at 1.0 m/s
Δv
189 m/s
PEAK COMMAND
30%
LOWEST COMMAND
18%
OUTSIDE THE ENGINE'S RANGE
0.0 s
ASKING FOR DOWNWARD THRUST
0.0 s
A lunar lander on one engine, flown to the pad by the quartic law with the time to go you choose. Above: the trajectory, uprange to the left; the pad is the cross at zero. Below: the thrust the law commanded (ink) and the thrust the engine delivered (orange), as fractions of full thrust, against the engine's floor and ceiling. Grey bars on the time axis mark where the law asked for thrust pointing below the horizon — which a lander cannot give. The flown trajectory is what the clamped engine produced.

At 90 s the law lands on the pad for 189 m/s and never leaves the engine's range. Shorten it. At 60 s it lands for 160 m/s — cheaper — but only because the figure clamps what the law asks for: for 6.8 s it wants less thrust than the floor allows, and for 5.2 s it wants thrust pointing below the horizon. At 35 s it asks for many times full thrust, cannot get it, and reaches the ground 16 m short at 47 m/s. Lengthen it instead and every trajectory is clean, but the cost climbs steadily — 237 m/s at 120 s, 302 m/s at 160 s — because the extra time is spent holding the lander up. For this divert the cheapest landing that never leaves the engine's range is at 82 s, for 177 m/s, exactly where the command first touches a limit. The optimum sits on a constraint, and a law that cannot see the constraints cannot find it. Raise the divert to 6 km and the cheapest clean landing costs 229 m/s at 97 s, while at 45 s the lander saturates and hits the ground 70 m short. Nothing in the law says in advance which times to go are flyable; it finds out by flying them.

Convex guidance

The alternative is to state the whole problem and hand it to a solver. The fuel-optimal landing problem is

with the start state given, , , a glide-slope cone keeping the vehicle above the ground on the way in, and above the dry mass. Here and are the thrust floor and ceiling, is vertical, the largest allowed tilt, the specific impulse and standard gravity. Everything in it is convex except one constraint: the thrust floor. The set of thrust vectors with is a hollow shell, and a shell is not convex.

G-FOLD — fuel-optimal large-divert guidance, from Açıkmeşe and Ploen's work at JPL in 2007 and developed with Blackmore and Carson — removes the difficulty by lossless convexification. Introduce a slack variable with and , and use in place of in the mass equation and the objective. The relaxed problem is convex, and the theorem at the heart of the method proves that its optimal solution has throughout: the relaxation gives up nothing. A change of variables, , and , makes the dynamics linear, and , and the thrust bounds become , which are bounded conservatively by Taylor expansions about a reference mass profile to stay convex. Discretised in time, the result is a second-order cone programme. Interior-point methods solve such programmes to the global optimum in a bounded number of iterations, or prove that no solution exists. The final time is found by a one-dimensional search outside.

What that buys is the thing the polynomial could not give: the fuel-optimal trajectory that respects every constraint, found in a predictable time on flight hardware, and a definite answer when a divert cannot be flown. The optimal thrust profile it finds is the three-dimensional cousin of the suicide burn — typically maximum, then minimum, then maximum, riding its bounds. G-FOLD was flight-tested on Masten Space Systems' Xombie vehicle in 2012 and 2013, and SpaceX has said that the Falcon 9 landing guidance also solves a convex optimisation problem on board in real time.

In Vivapse

The simulator gives a program two predictors. fc.predict({ landingBurn }) coasts the vehicle forward with drag, the forecast wind, the engine's spool-up and its throttle limits, and returns the latest ignition that still stops at the surface — ignitionAltitude, ignitionTime, and crashed if nothing is early enough. On real sites its ignitionTime is when to call fc.ignite(): the engine's dead time is inside it. Once lit, fc.stopPoint({ throttle, attitude }) says where the burn, held as it is, will bring the vehicle to rest. Flown the way the vehicle flies it, a planned burn stops within 0.2–0.4 m of its plan. Coming back down walks through both.

The reference programs close the loop around them. hop.js and full-mission.js plan the landing burn at 90 % throttle (LANDING_BURN = { engines: 1, throttle: 0.9, attitude: 'auto' }), refresh the plan every half second high up and every tick in the last second, and light on the tick it says. Then stopPointGuidance bisects the throttle between the floor and full ten times a second for the setting whose stop point is 12 m up, and leans the thrust a few degrees off retrograde to walk that point along and across onto the pad. Below 60 m or 20 m/s, touchdown() takes over: the constant-deceleration law above, aiming at about 1 m/s, with sideways steering from zemAccel — the zero-effort-miss law, for a target at rest, centred 1.5 s before touchdown and limited to a fifth of full thrust — and an engine cut timed for the 0.25 s tail-off.

The lunar and Mars programs, moon-landing.js and mars-landing.js, fly a braking phase of their own: the commanded acceleration kills the horizontal speed over the time 90 % of full thrust would take, and holds the descent rate below a hoverslam schedule, using fc.effectiveGravity rather than the full weight because at orbital speed the curvature of the path carries most of it. At 400 m they hand over to the terminal law of the figure, aimed at 1.5 m/s rather than at rest, and drop from three engines to one as soon as one can do the stopping.

What the simulator does not have is an optimiser. Nothing in it solves a convex programme; the reference programs are closed-form laws around predictors, which is what the flight-computer API makes easy. Since the third physics audit the predictors work about the Moon and Mars too — a predicted lunar impact lands within 0.02 s of the flown one — though the destination programs still carry their own integration. The physics they fly against is not forgiving: an ignition dead time of 0.2–0.5 s (a Merlin's is 0.3 s), a spool-up (0.5 s), throttle and gimbal slew limits, a 0.75 % engine-to-engine thrust spread, and, with realistic sensors, a radar altitude good to 0.2 % plus 5 cm.

The dead time is not a footnote. The flight computer's built-in guide gives a ten-line hoverslam and warns that on real sites a hand-made trigger must allow for it. Take the warning literally. With the snippet's trigger and throttle law on a simple vertical Hopper hop from Vandenberg, the engine is commanded on at 503 m, falling at 144 m/s, and the Hopper reaches the ground at 55 m/s: the Merlin's 0.3 s dead time and 0.5 s spool-up eat more height than the trigger's margin of 8 % plus 30 m. Triggering on fc.predict({ landingBurn: {} }) instead is not enough on its own, because with no throttle given it plans a full-throttle burn and leaves nothing to correct with: lit exactly at its ignitionAltitude, the same hop hits at 51 m/s. Lit 50 m above it, it lands at 2.1 m/s. The reference programs' 90 % does the same job more gracefully.

Try it

Choose the Hopper preset, which selects the Hop profile, and launch from Cape Canaveral with the weather set to Custom — wind, gusts and turbulence at zero — and Hardware dispersions switched off under Failures & sensors. Fly the Hop — suborbital hop to LZ-1 example. It climbs to about 20 km, falls tail-first on its grid fins, and lights its landing burn at T+221.7 s, 358 m up and falling at 145 m/s. The burn lasts 4.6 s and puts it down on the pad, 0.2 m from the centre at 1.3 m/s: Bullseye, with 10,144 kg of propellant left.

Now open the program, find the line near the landing guidance

const LANDING_BURN = { engines: 1, throttle: 0.9, attitude: 'auto' };

and change the throttle to 0.45 — a plan just above the Merlin's 40 % floor — and fly again. The planner sees a gentler burn and lights earlier, at T+218.4 s. The burn lasts 12.3 s instead of 4.6, burns 516 kg more, and the landing is graded Hard: 3.5 m/s vertical, 4.4 m/s sideways, 10 m off centre. A plan near the floor leaves the stop-point guidance almost nothing to throttle down with if the stop comes out high, and a long, gentle burn gives it less thrust to lean on when it steers. Then try 1.0: now there is nothing in hand in the other direction, but the predictor is accurate enough that the Hopper still lands on the pad, graded Good. The 90 % the programs use is a choice about margins, and this is how to see what it buys.

What carries forward

Every descent in this lesson happened in a vacuum or through air that only helped a little. Mars is different: most of the arrival speed has to be taken off by the atmosphere before an engine can finish the job, and the atmosphere is thin enough that for a heavy vehicle it may not manage. Entry, descent and landing on Mars is about that hand-over, and about what it does to the burn at the bottom.