Skip to content

11.8 — Landing a Booster

A Falcon 9 first stage separates at about 70 km altitude travelling at roughly 2 km/s, and eight minutes later it is standing upright on a drone ship 600 km downrange, having touched down at under 2 m/s within a couple of metres of the target.

It has one attempt. There is no go-around, no hover, and it cannot even throttle down far enough to hover.

This chapter states the problem properly, computes the burn from scratch, and explains how the guidance is actually solved.

Why it is hard

Four constraints, and each one alone would be manageable.

1. The vehicle cannot hover. A single Merlin engine produces 845 kN at sea level and throttles to about 40 %, giving a minimum of 338 kN. The empty stage plus residual propellant is about 25 tonnes, weighing:

W = 25{,}000\times9.81 = 245\ \text{kN}

\frac{F_{\min}}{W} = \frac{338}{245} = 1.38

Even at minimum throttle the thrust exceeds the weight by 38 %. The vehicle accelerates upward if it fires too early and crashes if it fires too late.

\boxed{\text{There is exactly one correct moment to start the burn.}}

2. Propellant is nearly exhausted. The landing burn has a margin of a few seconds. Any error must be corrected within that.

3. The target is small and may be moving. A drone ship is 91 by 52 metres, in ocean swell, and its station-keeping is good to a few metres.

4. The atmosphere is in the way, providing drag that must be modelled and aerodynamic forces that must be controlled.

The suicide burn

Also called a hoverslam. The vehicle falls with engines off until the last possible instant, then burns at full available thrust to arrive at zero velocity exactly at the surface.

Why not burn earlier and descend gently? Because gravity losses (Chapter 11.7). Every second spent thrusting costs g of delta-v, so the cheapest descent is the one that thrusts for the shortest possible time.

Deriving the burn

Take a vehicle at velocity v (downward) at altitude h, decelerating at constant net rate a_{\text{net}}.

a_{\text{net}} = \frac{F}{m}-g

From the kinematic equation (Chapter 1.2), for the velocity to reach zero:

0 = v^2-2a_{\text{net}}h_{\text{burn}}

\boxed{h_{\text{burn}} = \frac{v^2}{2a_{\text{net}}}}

And the burn duration:

t = \frac{v}{a_{\text{net}}}

Worked example

A stage at 2 km altitude falling at 300 m/s, mass 25 t, single engine at 845 kN.

a_{\text{thrust}} = \frac{845{,}000}{25{,}000} = 33.8\ \text{m/s}^2

a_{\text{net}} = 33.8-9.81 = 24.0\ \text{m/s}^2

h_{\text{burn}} = \frac{(300)^2}{2(24.0)} = \frac{90{,}000}{48.0} = 1875\ \text{m}

t = \frac{300}{24.0} = 12.5\ \text{s}

Ignite at 1875 m and burn for 12.5 seconds.

Now check the sensitivity. Ignite 1 second late, so the burn starts at:

h = 1875-300-\frac{1}{2}(9.81)(1)^2 = 1875-305 = 1570\ \text{m}

and the speed is now 300+9.81 = 310 m/s, requiring:

h_{\text{needed}} = \frac{(310)^2}{2(24.0)} = 2003\ \text{m}

You need 2003 m and have 1570. The vehicle hits the ground at:

v_{\text{impact}} = \sqrt{v^2-2a_{\text{net}}h} = \sqrt{96{,}100-2(24)(1570)} = \sqrt{96{,}100-75{,}360} = \sqrt{20{,}740} = 144\ \text{m/s}

144 m/s, from being one second late.

And one second early? The vehicle reaches zero velocity at about 200 m altitude, then — because it cannot throttle below 1.38 g — starts accelerating upward. It must shut down, fall again, and restart, which wastes propellant it does not have.

The mass changes during the burn, which the constant-acceleration treatment above ignores. Burning 845 kN at I_{sp} = 282 s consumes:

\dot{m} = \frac{F}{I_{sp}g_0} = \frac{845{,}000}{282\times9.81} = 305\ \text{kg/s}

Over 12.5 seconds that is 3.8 tonnes, so the mass falls from 25 t to 21.2 t and the acceleration rises from 24.0 to 30.1 m/s². Real guidance integrates this properly, and the effect shortens the required burn by about 10 %.

The full descent profile

Falcon 9's return-to-launch-site sequence:

Stage separation, about 70 km altitude, 2000 m/s.

Boostback burn — three engines, about 30 seconds, reversing the horizontal velocity to fly back toward the launch site. Costs about 1500 m/s.

Coast to apogee at about 130 km, above the atmosphere.

Entry burn — three engines, about 20 seconds at roughly 70 km altitude, slowing from about 2000 m/s to 800 m/s. This is not for the landing; it is to reduce the heating and dynamic pressure on the way down.

Aerodynamic phase — grid fins deploy and steer the vehicle. Terminal velocity is reached at around 300 m/s as drag balances weight.

Landing burn — one engine, about 30 seconds, the suicide burn computed above.

Legs deploy in the final seconds.

Touchdown at under 2 m/s.

Total delta-v for recovery: about 2000 m/s, which is the payload penalty discussed in Chapter 11.7.

Grid fins

Four titanium lattice fins near the top of the stage, folded during ascent and deployed for entry.

Why a lattice. A conventional flat fin has a large hinge moment — the aerodynamic force acts far from the pivot, requiring powerful actuators. A lattice fin's individual cells each generate lift, and the centre of pressure sits close to the hinge line, so the actuator forces are small for the control authority produced.

And they work supersonically, where a conventional fin would suffer shock-induced separation. The lattice's short chord means the shocks form on individual cells rather than across the whole surface.

They are titanium, machined from a single forging, after the original aluminium fins caught fire on reentry. Titanium's melting point of 1668 °C and its strength at temperature make it survivable without ablative coating, and the fins are reused without refurbishment.

Placed at the top because that is far from the centre of mass, giving a long moment arm.

Thrust vectoring

The engines gimbal by a few degrees, which is what actually controls the attitude.

And the geometry is unstable. The thrust acts at the bottom of the vehicle, below the centre of mass, which is the same configuration as balancing a broom on your palm. Any angular deviation grows.

Compute the timescale. For an inverted pendulum of length L from pivot to centre of mass:

\tau = \sqrt{\frac{L}{g}}

For L = 20 m:

\tau = \sqrt{\frac{20}{9.81}} = 1.43\ \text{s}

The vehicle falls over on a 1.4-second timescale if uncontrolled. The control loop runs far faster than that, but the margin is not enormous.

Landing legs deploy in the last seconds, are carbon fibre with aluminium honeycomb, and give a base of 18 m. The vehicle's centre of mass must stay inside that footprint at touchdown, which sets the maximum acceptable tilt.

Convex optimisation

The interesting part is not the physics but how the trajectory is computed.

The problem to solve: find the thrust profile \vec{T}(t) that takes the vehicle from its current state to the target with zero velocity, minimising propellant, subject to:

  • Thrust magnitude bounds: T_{\min} \leq |\vec{T}| \leq T_{\max}
  • Thrust direction limits (gimbal range)
  • Glide slope — stay above a cone from the landing site
  • Mass depletion — cannot use more propellant than is carried

The difficulty: the constraint |\vec{T}| \geq T_{\min} is non-convex.

Why that matters. A convex problem has one minimum and can be solved reliably in guaranteed time. A non-convex problem may have many local minima, and an algorithm can get stuck in a bad one — which is unacceptable when the answer is needed in milliseconds and there is no second chance.

The set of allowed thrust vectors is a spherical shell — magnitude between T_{\min} and T_{\max} — and a shell is not convex, because the straight line between two points on opposite sides passes through the forbidden hollow centre.

Lossless convexification

Behçet Açıkmeşe and Lars Blackmore, working at JPL around 2007, found the fix, and it is elegant.

Introduce a slack variable \Gamma representing the thrust magnitude, and write the constraints as:

|\vec{T}| \leq \Gamma, \qquad T_{\min} \leq \Gamma \leq T_{\max}

Now the feasible set is a solid cone, which is convex.

And here is the theorem that makes it work: they proved that the optimal solution of the relaxed convex problem always has |\vec{T}| = \Gamma exactly, so it is automatically a valid solution of the original non-convex problem.

\boxed{\text{The relaxation loses nothing. Hence "lossless".}}

The consequences are practical and large:

Guaranteed convergence to the global optimum.

Bounded solution time — interior-point methods solve these in a predictable number of iterations.

Runs in milliseconds on flight hardware.

Infeasibility is detected, rather than the algorithm silently returning a bad answer. The vehicle knows if it cannot make the target.

The algorithm is called G-FOLD — Guidance for Fuel-Optimal Large Divert — and it was demonstrated on the Masten Xombie testbed in 2012, computing trajectories in real time and executing 750 m divert manoeuvres.

It is the reason precision landing is possible at all. Apollo landed with a several-kilometre error ellipse and a human pilot doing the final approach. Modern powered descent achieves metres, autonomously.

The control loop

Every 100 milliseconds, or faster:

1. Estimate the state. Fuse inertial measurement, GPS, radar altimeter and — near touchdown — optical navigation, through a Kalman filter. The IMU drifts, GPS updates slowly, radar is noisy; the filter combines them optimally given the known error characteristics of each.

2. Re-solve the trajectory. Given the current state, compute the optimal remaining path.

3. Apply the first control input, then discard the rest of the plan.

4. Repeat.

This is model predictive control, and step 3 is the important one. The plan is recomputed continuously from the actual state, so disturbances, model errors and wind are corrected automatically rather than accumulating.

Compare with an open-loop approach — compute a trajectory before flight and follow it. A 10 m/s wind at 1 km would produce a large miss with no way to recover.

And the whole descent is autonomous. There is no human in the loop and the round-trip latency to a drone ship would make one impossible anyway.

Where it goes wrong

The early failures are instructive, and SpaceX published them.

CRS-5, January 2015. The grid fin hydraulic fluid ran out before touchdown, control was lost, and the stage hit the drone ship hard. Fix: carry more fluid.

CRS-6, April 2015. A stuck throttle valve caused the vehicle to overcorrect in a lateral oscillation and it toppled after touching down. Fix: valve redesign.

Jason-3, January 2016. A landing leg's collet failed to latch, probably from ice in the mechanism after the vehicle sat in fog on the pad, and the stage tipped over. Fix: leg redesign.

Falcon Heavy centre core, February 2018. Two of three engines failed to relight for the landing burn, because the igniter fluid ran out. Fix: more igniter fluid.

Successful landing, December 2015 — and by 2024 the success rate exceeds 99 %, with over 300 recoveries.

Notice how many of the failures were consumables and mechanisms rather than guidance. The mathematics worked from early on; the engineering took longer.

Elsewhere

Mars landing is a different problem entirely.

The atmosphere is 1 % of Earth's — thick enough to require a heat shield and to cause serious heating, and too thin for parachutes alone to slow a heavy vehicle to a safe speed.

Curiosity's sky crane, 2012, is the response: heat shield, then supersonic parachute, then a rocket-powered descent stage that hovers and lowers the rover on cables before flying away to crash at a safe distance.

Why not land the descent stage itself? Because a rover needs to be at ground level with wheels down, and a landing platform would need ramps that might not deploy on rough terrain.

Perseverance added Terrain Relative Navigation in 2021 — the vehicle photographs the surface during descent, matches it against an onboard map, and diverts to avoid hazards. It landed within 5 m of its target in Jezero Crater, a site that would have been rejected as too dangerous without it.

Lunar landing has no atmosphere at all, so it is pure propulsive descent from orbit — and correspondingly expensive, at about 1.9 km/s.

Blue Origin's New Shepard lands its booster from a suborbital flight, which is much easier: lower speed, no downrange distance, and a fixed pad.

Starship aims to land both stages, with the booster caught by the launch tower rather than carrying legs. The first successful catch was in October 2024. Removing the legs saves mass, which the rocket equation converts directly into payload.

Where this shows up in your life

Falling launch costs. Reuse has driven the cost per kilogram to low Earth orbit down by roughly an order of magnitude, which is why satellite internet, large constellations and small-satellite science missions became viable.

Convex optimisation, developed and proven here, is now used in autonomous vehicle path planning, robotics, portfolio optimisation and power grid dispatch.

Model predictive control runs chemical plants, engine management systems, and building climate control.

Kalman filtering is in your phone's navigation, in aircraft autopilots, and in every GPS receiver.

And the general lesson is one of the more interesting in engineering: the problem was solved not by better hardware but by reformulating it into a class of problem that can be solved reliably. The rocket did not change. The mathematics did.

What the next chapter fixes

Everything in this Part has assumed the distances and masses are known. They had to be measured, and almost nothing in astronomy can be measured directly. Chapter 11.9 covers how: how telescopes work across the spectrum and what limits them, how interferometry gives resolution far beyond a single dish, what spectroscopy reveals about objects nobody will ever visit, and the distance ladder — a chain of methods, each calibrating the next, that reaches from the Moon to the edge of the observable universe.