DELTA-SIERRAMARSEXPLORE · UNDERSTAND · SETTLE
Support my work
BIBLE MARS — REFERENCE DOSSIER

Terrain-relative navigation, hazards and Mars landing-site selection

MEASURED / DEMONSTRATEDENGINEERINGEXPLICIT SCENARIO

See, recognize and avoid: how the vehicle can still choose its terrain

The problem addressed here concerns autonomous localization and safe-site selection when Earth cannot pilot the final minute.

The central observables are descent images, position error, correlation quality, hazard map, lateral divert margin and time remaining.

Mars 2020 post-flight analysis separates roughly 60 m localization requirement, roughly 33 m pre-landing estimate and roughly 5 m final measured distance from the selected target

Landing on Mars without GPS: when an image becomes a position

On Earth, a phone can ask a purpose-built satellite constellation where it is. Mars has no global GPS waiting for an arriving lander. During the final minutes, the spacecraft has an inertial estimate, radar or lidar measurements depending on the architecture, maps prepared before launch and only seconds to make sense of what a descent camera sees. Terrain-relative navigation turns visible surface patterns into a position estimate relative to an onboard map. This is not consumer image recognition; it is a real-time navigation chain in which every calibration or timing error ultimately becomes metres on the ground.

Mars 2020 provides the reference Mars demonstration. Perseverance’s Lander Vision System captured the terrain after heat-shield separation, projected imagery using estimated altitude and attitude, and matched it against onboard orbital maps. JPL describes source HiRISE imagery near 30 cm/pixel and onboard map products at 12 and 6 m/pixel for coarse and fine localization. The output was not a human-like understanding of a landscape. It was a map-relative position estimate and uncertainty that guidance could use.

Navigation, guidance and control must be kept distinct. Navigation asks: where am I, how fast am I moving, what is my attitude and how uncertain are those answers? Guidance asks: from that state, what path or target should I select? Control asks: what actuator commands will make the vehicle follow the chosen path? TRN first improves navigation information. Better information lets guidance choose a safe reachable target and lets control execute the divert.

Safety itself must be defined. A hazard map is more than red and green pixels. Each cell encodes prior decisions about slope, roughness, rocks, dunes, map uncertainty and vehicle tolerance. TRN helped Mars 2020 accept Jezero despite cliffs, dunes and boulder fields that made the site too risky for earlier landing approaches. A settlement adds artificial hazards: a naturally flat area can still be forbidden because it sits near a habitat, propellant tank, solar array, antenna or rover route.

Jezero hazard map prepared for Mars 2020 terrain-relative navigation. Colors distinguish more hazardous terrain from preferred landing areas.
Jezero hazard map prepared for Mars 2020 terrain-relative navigation. Colors distinguish more hazardous terrain from preferred landing areas. Credit: NASA/JPL-Caltech.

A navigation system does not seek only latitude and longitude; it seeks a state. That state includes at least position, velocity and attitude, together with sensor biases and uncertainty. An IMU measures accelerations and rotations at high rate. By integrating those measurements, the computer propagates its best estimate between external observations. But a small bias integrated for several seconds becomes a velocity error and then a position error. Pure inertial navigation therefore drifts and must be corrected by observations of the outside world.

At Mars those observations can come from radar altimetry, terrain images, the Sun, stars or radio data depending on mission phase. During landing, a camera sees a patch of ground that rotates, grows and changes contrast rapidly. The computer must decide which details in the image correspond to which details in its reference map. A cliff, crater or boulder field is therefore not only geology; it becomes information used to correct the estimated state.

Vertical and horizontal knowledge are not measured in the same way. An altimeter can provide distance to the surface while horizontal location remains uncertain; a camera can identify a horizontal region while being affected by illumination geometry. Robust architecture fuses sensors because their weaknesses differ. Fusion is the key word: the camera does not replace the IMU; it prevents inertial error from growing without bound.

Navigation is also a timing problem. An image taken at time t describes terrain the vehicle has already moved beyond when processing finishes. If acquisition, matching and command generation took 500 ms while horizontal speed were 100 m/s, the vehicle would travel about 50 m during processing. That is an illustration, not a Mars 2020 latency figure. It shows why measurements need precise timestamps and why the estimated state must be propagated to the present before a correction is used. Guaranteed latency can matter as much as laboratory accuracy when the final descent is consuming decision time very quickly.

The same architecture must remain observable after flight. Engineers need enough recorded imagery, inertial data and filter state to reconstruct why the vehicle accepted or rejected landmarks. Without that record, a successful landing can hide a fragile algorithm and a bad landing can be impossible to diagnose. Data return is therefore part of navigation maturity: every descent should improve the evidence available for the next one.

Perseverance: from a coarse three-image solution to a reachable target

The JPL landing documentation gives a useful clock. The Lander Vision System operated roughly between 4.2 and 2.2 km above the surface and was designed to produce localization of about 40 m in less than ten seconds. JPL Robotics describes a coarse mode matching fifteen landmarks across three images, followed by a fine mode that can process up to roughly 150 landmarks per image and fuse them with inertial data. These numbers belong to Mars 2020 rather than to every future lander, but they reveal the character of the problem: seconds of computation, finite imagery, radiation-qualified hardware and a decision that cannot be reviewed by Earth in real time.

Perseverance could then shift its touchdown point by up to about 600 m according to the mission press kit. That lateral reach turns hazard avoidance into an optimization problem. The safest pixel is useless if the vehicle cannot dynamically reach it with the altitude, velocity and propellant remaining. The onboard safe-target logic therefore has to rank candidates inside a reachable set rather than simply identify the globally safest terrain.

JPL Robotics reports LVS map-relative position error below 40 m and notes that Perseverance touched down about 5 m from the point targeted by LVS. Those five metres should not be misrepresented as a universal TRN error. JPL explicitly attributes the result to several errors being small at once: map distortion, sensor alignment, correlation quality and navigation after the visual estimate. Engineering budgets therefore keep map error, localization error, inertial propagation, guidance error and propulsion dispersion separate.

A root-sum-square example illustrates the bookkeeping if errors are provisionally treated as independent. Suppose localization contributes 20 m, map error 15 m and residual guidance error 10 m. Combined RSS is √(20² + 15² + 10²) = √725 ≈ 26.9 m. The square-root symbol √ means the positive square root. This calculation is only justified when the errors are sufficiently independent; common biases and correlations can make RSS optimistic. Covariance modeling and end-to-end tests are what reveal those dependencies.

LCAM’s descent image of the departing heat shield is almost poetic: hardware falls away over Mars while the camera that has just been exposed begins giving the vehicle the measurements needed to recognize its world. Behind the image sits a strict metrology chain—short exposure, calibrated optics, timing, attitude knowledge and common map reference. A picture does not directly provide a position. The navigation system constructs one.

Mars 2020 provides unusually useful numbers. JPL documentation describes a coarse localization phase using about fifteen landmarks across three images, followed by a finer phase capable of using up to roughly one hundred and fifty landmarks per image. The source map includes HiRISE imagery that can reach about 30 centimetres per pixel and is transformed into lower-resolution products suitable for onboard computation. The objective is not to carry all orbital science data in flight software but a compact representation that can answer in real time.

Perseverance’s Landing Vision System was designed for map-relative localization error below roughly 40 metres within its documented performance envelope. The rover ultimately touched down about five metres from the point the system selected during descent, a result better than the requirement but not a universal five-metre promise. A particular flight includes favourable conditions and dispersion. Requirement, flight result and future capability are three different things.

The process also shows why precision is not an end in itself. TRN uses localization to move the target toward terrain judged safer. Perfect position knowledge without a hazard map or authority to divert would not save the vehicle. Conversely, a perfect hazard map is useless if position uncertainty is larger than the safe patches. Localization, mapping and guidance must be designed together.

Teaching uncertainty budget.σtot ≈ √(σ₁² + σ₂² + σ₃²)

Root-sum-square combination is appropriate only when contributions can reasonably be treated as independent; correlated biases require a different model.

LCAM image during Perseverance descent: the heat shield falls away while the vision system begins map-relative localization.
LCAM image during Perseverance descent: the heat shield falls away while the vision system begins map-relative localization. Credit: NASA/JPL-Caltech/MSSS.

The onboard map is therefore a deliberately engineered product rather than a raw photograph. Resolution, landmark selection, hazard classes, coordinate frames and map uncertainty all affect what flight software can infer. A higher-resolution image is not automatically better if it consumes too much memory or computation, while an oversimplified map may discard the features needed for localization. The design problem is to preserve the information that changes a landing decision, not to maximize pixels for their own sake.

How a vision system can be fooled two kilometres above the surface

A TRN system can fail by finding no match, which is dangerous but comparatively easy to detect. The subtler failure is a false match: the algorithm reports a confident-looking answer at the wrong location. Repetitive craters, similar ridges, lighting differences or local map distortion can create ambiguity. Confidence logic therefore needs more than one correlation score. It should examine agreement among landmarks, compatibility with inertial state, temporal continuity and the geometry of the solution.

Lighting is an adversary too. Orbital mapping may have been acquired at a different season, local time and solar angle from the landing. Shadows change apparent feature shape. Atmospheric dust reduces contrast; later, engine plumes may obscure the surface. Cameras must survive vibration and thermal extremes and then transition from protection behind a heat shield to the external scene. Algorithms cannot depend on perfectly illuminated photography.

Timing deserves its own error budget. An image is exposed, read, transferred, processed, correlated, fused with inertial measurements and sent to guidance. If each stage takes slightly longer than planned, the spacecraft may already have moved tens or hundreds of metres before the result is used. Measurements therefore need precise timestamps and state propagation. The system must know where it was at image time and propagate that estimate correctly to command time.

Failure response should be tiered. Complete camera loss can force reversion to inertial/radar navigation and a more conservative landing zone. Partial degradation may reduce allowed divert. Doubt about map validity may favor targets whose safety is robust to cartographic error. Inertial inconsistency may require sensor isolation or redundancy. This is FDIR, and it has to be designed before launch; Earth cannot take over during a Mars landing.

Uncertainty can be represented through covariance, a statistical description of errors and their correlations. In a simplified example with independent 20 m, 15 m and 10 m errors on three axes, a root-sum-square magnitude is √(20²+15²+10²) = √725 ≈ 26.9 m. This is not a real Mars navigation ellipse; it simply illustrates why independent errors are not always added linearly and why the flight computer carries an estimate of what it does not know.

The most dangerous measurement can be one that is precise but wrong. If an image is matched to the wrong map pattern, the filter may receive a numerically confident correction that is geographically disastrous. Algorithms therefore test match quality: number of consistent landmarks, residuals, geometry, continuity with the prior state and rejection thresholds. Faster computation permits more hypotheses, but safety also comes from being able to say ‘I do not know’ when an image does not justify a correction.

Low-angle lighting, dust, seasonal shadows, surface change, motion blur, saturation and obscuration can alter appearance. A map years old may remain excellent for large relief while being imperfect at a site changed by a storm, a new impact or base operations. Settlement creates a paradox: an occupied site can be instrumented more heavily, yet it can also be modified by roads, plumes, excavation and equipment.

The software must also manage measurement age. A correction that was valid when an image was exposed can become misleading if applied after a long processing delay without propagating the vehicle state. Flight algorithms therefore associate observations with time, propagate inertial state between updates and reject information that no longer fits the predicted motion. This is one reason deterministic execution time matters: an algorithm that is brilliant on average but occasionally stalls during the last minute of descent may be harder to certify than a slightly less accurate method with bounded timing.

Camera calibration is another hidden dependency. Focal length, optical distortion, alignment with the inertial frame and timing must be known well enough that a pixel direction can become a line of sight in the vehicle coordinate system. Thermal changes, vibration or replacement of a camera can alter those parameters. A settlement fleet therefore needs calibration procedures and configuration tracking just as much as clever image matching.

The safest response to an uncertain match may be to continue on inertial propagation for a short period rather than force a correction. That choice consumes uncertainty margin, so software needs explicit thresholds for when another image is required, when a target must be enlarged, and when the current solution is no longer safe enough for precision diversion. Graceful degradation is a designed mode, not merely an error message.

For a human lander, the safe zone becomes infrastructure

An early cargo mission can target a broad plain. An established settlement will prefer to land close to stores, workshops and habitats to reduce surface logistics. Precision becomes more valuable at exactly the moment when the consequence of error becomes larger. Site selection therefore evolves from a natural-hazard map into an operational map containing exclusion zones, approach corridors, propellant farms, power lines, solar arrays, antennas, mobile vehicles and the scars left by previous landings.

The map must also evolve. Dust moves, rovers dig tracks, construction creates berms and previous touchdowns can scour or contaminate surfaces. A map prepared two years before launch is not sufficient for a working base. The settlement needs a configuration-controlled update chain using orbital imagery when available, rover surveys, lidar, local cameras, possible aerial reconnaissance and surveyed beacons. The arriving vehicle must know which map version it uses and when each landing cell was last certified.

A prepared pad does not end the problem. It can control roughness and erosion but becomes a comparatively small target. If unavailable, the vehicle needs alternates. A robust architecture may define a nominal prepared pad, a secondary prepared area, a tertiary characterized natural site and an abort site farther away. Lateral reach and propellant reserve should be designed around those options rather than around a single perfect circle on a map.

Repeated operations can eventually add local aids unavailable to Perseverance—radio beacons, lidar reflectors, transponders or a local positioning network. Those aids should improve precision without becoming a single point of failure. A base blackout must not make a descending vehicle blind. Terrain/inertial navigation still needs enough autonomous capability to reach a safe fallback zone when local infrastructure disappears.

A first human landing must avoid circular dependence: it cannot require precision beacons, a ground radar and a prepared pad if installing them already requires a heavy lander. The strategy must grow in stages. Early missions depend more on orbital mapping, onboard autonomy and broad safe terrain. Later cargo can deploy beacons, weather stations and artificial landmarks. A mature base can maintain a landing zone remapped after each event, monitored continuously and perhaps supported by local radio aids.

That progression turns a site into infrastructure. A beacon is useful only if its power, clock, integrity and position are known; an optical marker must remain visible through dust; a ground radar must sit outside dangerous ejecta zones; a radio link must survive terrain masking and local plume effects. Redundancy therefore does not mean ten copies of one sensor but a combination of measurement modes with different common-cause failures.

Settlement also adds traffic. Two vehicles should not converge on the same zone if the first has damaged the surface or filled the second vehicle’s sensors with dust. Approach corridors, exclusion zones, updated maps and knowledge of mobile obstacles become airfield-management problems. Precision navigation becomes not only a vehicle technology but a collective safety function of the settlement.

Local weather completes the infrastructure. Pressure, temperature, wind and dust can change both terminal trajectory and terrain appearance. A station near the pad provides context but does not measure every layer the vehicle crosses kilometres above the ground. Forecasts, orbital observations and onboard sensors therefore remain complementary. A fleet can turn each arrival into data for the next one: measured navigation error, pad condition, visibility, wind, dust production and beacon performance. The landing site becomes an instrumented system that learns from operations rather than a fixed coordinate on a map.

The infrastructure itself must have integrity monitoring. A beacon that silently drifts in time or position can be worse than no beacon because it injects confident but false information. Local aids need self-tests, cross-checks and a way for the vehicle to down-weight or ignore them when they disagree with inertial and optical evidence. More infrastructure improves precision only if the system can also detect when that infrastructure has become untrustworthy.

Prepared sites can also use features that help both humans and machines: surveyed landmarks, high-contrast patterns, reflectors or radio aids whose coordinates are tied to the same local reference frame. Yet every aid must be maintainable after dust deposition and repeated landings. The more the system depends on local infrastructure, the more that infrastructure becomes part of the pre-landing checklist.

The right metric is not average accuracy but probability of avoiding the wrong ground

Navigation presentations favor a single number because 40 m, 20 m or 5 m are easy to compare. Landing safety cares more about distribution tails. A system that reaches 5 m most of the time but produces a catastrophic false localization once in a thousand cases may be less acceptable than one that is consistently within 30 m and tightly bounded. Useful metrics therefore include no-match rate, false-match probability, high-percentile error, divert availability, map integrity and conditional probability of touching a hazard.

Validation has to reproduce diversity rather than beauty. Synthetic images, terrestrial field campaigns, orbital archives, lighting transforms, simulated dust, timestamp errors and sensor faults should populate the test set. The important cases are often feature-poor, repetitive, saturated or misaligned scenes that make the algorithm uncomfortable.

This is also software assurance: traceable requirements, an independent validation dataset, controlled versions of maps and algorithms, deterministic critical functions, recorded decisions and the ability to replay a landing. Each actual arrival can then improve the next one. Descent imagery, map errors and true trajectories become engineering data for a growing settlement rather than disposable mission telemetry.

The next chapter moves down the final few hundred metres. Even after navigation chooses the right spot, rocket exhaust can turn that spot into a hazardous environment. Terminal descent must therefore connect geometric precision with surface physics: a target is not truly safe unless the lander, nearby infrastructure and the ground can survive the last seconds of thrust.

Average performance can be misleading. Imagine, only as a reasoning example, a system that usually lands within a few tens of metres but has a very small probability of producing a multi-kilometre error. That tail might be acceptable for some isolated robotic missions; for a vehicle carrying dozens of people toward a base it can dominate risk. Engineers therefore need the error distribution, the conditions that produce outliers and the way the system behaves when confidence falls.

Site selection must incorporate the same statistics. A theoretically ideal patch surrounded by cliffs and boulders leaves little margin for degraded navigation. A less scientifically attractive plain offering kilometres of alternate safe solutions may be better for early human rotations. As precision and infrastructure improve, the usable surface can become more constrained. Navigation performance and settlement strategy therefore evolve together.

Finally, separate three metrics: knowing position, choosing a safe target, and reaching that target despite disturbances. The first belongs to state estimation, the second to perception and hazard mapping, the third to guidance and control. Calling all three simply ‘TRN’ hides the interfaces where errors can arise. Those boundaries should remain explicit because verification requirements are often born at subsystem interfaces.

This leads naturally to levels of service. A base may define a nominal target, a nearby alternate, a distant alternate and, for some mission profiles, a decision to remain in orbit or abort before an irreversible commitment. Each option has propellant, navigation and weather thresholds. The vehicle must know not only where it is but which options remain physically reachable. Certification then covers the decisions permitted at each confidence level, not just the nominal accuracy of the localization sensor.

Finally, the base should retain configuration history: map version, flight-software version, camera calibration, beacon positions, landing-zone condition and atmospheric context. Without that traceability, comparing two landings becomes misleading because the differences are unknown. Precision is therefore not just a number produced in real time; it is a capability that must be explained after flight, audited and improved before the next arrival.

A final safety argument should therefore connect sensor performance to hazard geometry. If safe patches are hundreds of metres wide, a given localization error may be tolerable; if the only clear pad is narrow and surrounded by equipment, the same error may be unacceptable. Accuracy has no meaning without the spatial scale of the decision it is supposed to support.

That relationship should be recalculated whenever site geometry changes. A new habitat, berm, crane or parked vehicle can turn yesterday’s acceptable error ellipse into today’s collision risk. Maintaining navigation safety therefore requires configuration control of the ground environment as well as flight software.

Terrain-relative navigation asks a simple question: “which part of the map is actually below me?”

A vehicle can know its inertial trajectory and still be too uncertain to know whether the touchdown point lies on safe terrain. Terrain Relative Navigation — TRN — compares observations during descent with a map prepared before flight. The objective is not merely latitude and longitude; it is determining whether the current path leads to an allowed region or to a mapped hazard.

On Mars 2020, a downward-looking camera observed the surface after heat-shield separation. The system matched terrain features to onboard maps, estimated position, and supported selection of a safer reachable region. NASA TechPort now lists the TRN project as a Completed Technology Project and records its successful Perseverance landing demonstration on February 18, 2021.

That flight result is powerful evidence because the technology operated at Mars. It is still specific to a robotic mission and its dynamics. A human-scale lander produces more dust, has different inertia, may require a much larger touchdown area, and faces much more severe consequences if the navigation solution is wrong.

A safe site is a reachable region, not a perfect pixel

Terrain-relative navigation compares onboard imagery with a stored map to reduce position error and identify hazards. Its useful output is not simply a coordinate: guidance needs a set of landing areas that remain reachable with the fuel, time and divert authority still available. A perfectly flat patch is irrelevant if the vehicle can no longer manoeuvre to it. Hazard maps must also resolve features at the scale that matters to landing gear, ground clearance and vehicle centre of gravity rather than at an arbitrary cartographic resolution.

Confidence in localisation changes as observations arrive. Ambiguous image matching, poor illumination or an outdated map can increase uncertainty just as decision time is disappearing. The system should then prefer a slightly less optimal but better-characterised region instead of pursuing a target whose safety can no longer be demonstrated. For human missions, the definition of safe also extends beyond touchdown: slope, obstacles and access to surface assets determine whether the crew can actually use the site after EDL.

A localisation map and a hazard map serve different purposes

A localisation map needs features a sensor can recognise: craters, texture, contrast, or relief. A hazard map encodes slopes, rocks, weak ground, terrain discontinuities, or existing infrastructure. The same orbital data can support both, but their criteria differ. A visually distinctive region can be dangerous, while a safe plain can be poor for image matching.

The vehicle also needs a reachable set. At each instant, estimated state, velocity, divert authority, and propellant define the touchdown points that remain physically possible. Hazard selection should operate inside that set. Choosing a perfect site outside the reachable envelope is an optimisation failure.

Conceptual calculation — position margin inside a safe zone

Suppose a circular safe zone has radius 500 m. If the 3σ position error is 180 m and the nominal aim point lies 200 m from the centre, a simple geometric margin to the boundary is 500 − 200 − 180 = 120 m. Real guidance uses a two-dimensional covariance and dynamics; the example shows why “the nominal point is inside” is not enough when uncertainty still overlaps hazards.

Dust and lighting argue for more than visible-light imaging

Mars 2020 demonstrated optical TRN inside a defined operating envelope. Work on broader seasonal, lighting, and dust conditions has explored lidar and high-performance computing. NASA TechPort’s Mars Intelligent Landing System project described a photon-counting lidar combined with terrain-navigation and hazard-detection algorithms intended to support landing in more challenging conditions. TechPort lists that effort as completed after a short 2025 project period; it should not be presented as an operational flight system.

Useful redundancy comes from different modalities. An IMU propagates state through an optical outage; lidar supplies geometry; radar provides altitude and velocity; cameras provide rich texture. Each sensor brings a different failure mode. The architecture should use that diversity rather than simply duplicating cameras.

Computation must respect the time-to-go

TRN cannot spend several seconds processing an image if the lander travels hundreds of metres during that delay. The chain includes acquisition, image correction, feature extraction, map matching, state update, and divert decision. Processing latency must be part of the geometry: a perfect position solution based on an old image may already be operationally stale.

The computer also needs a defined failure mode for poor correlation. Robust software outputs a confidence measure and can admit that it does not know. It may then continue inertially toward a conservative target rather than inventing location certainty. The critical test is not only success on easy scenes but behaviour when map and image disagree.

Four terrain scenarios

The onboard map is outdated

Dust redistribution or new infrastructure can alter appearance. Stable geological features should carry more weight than temporary details. A settlement may need routine hazard-map updates around active landing zones.

The safest site is reachable only with a large divert

Guidance must compare safety benefit with propellant cost. If the divert consumes reserve required for engine-out recovery, a slightly less ideal but closer region may be the safer overall decision.

The camera sees feature-poor terrain

Correlation covariance should grow. The system can wait for a better scene, use another modality, or widen its uncertainty. The unsafe behaviour is to keep nominal confidence when evidence has weakened.

A local beacon disagrees with terrain matching

Near a base, radio or optical beacons may offer an independent reference. Software needs explicit confidence, calibration date, and failure logic for both sources. A mis-surveyed beacon should not automatically override a coherent terrain solution.

References: NASA TechPort Terrain Relative Navigation, a completed project demonstrated by Mars 2020; NASA TechPort Mars Intelligent Landing System, a completed technology effort describing lidar/TRN integration for broader landing conditions. The two sources represent different maturity levels and are labelled accordingly.

trn reachable safe set
Chapter-specific synthesis diagram.

Case study — bound divert by the time actually available

A simple upper bound on divert radius is r ≈ v_h t. With v_h = 25 m/s and t = 35 s, r ≈ 875 m before acceleration, braking and attitude constraints. v_h is available horizontal velocity, t remaining time and r ideal reachable distance.

An imperfect map or degraded image can reduce position confidence just as altitude disappears. The system must select a safe point inside the truly reachable set, not merely the flattest image pixel.

Synthetic and real imagery, lighting variations and sensor faults measure localisation error, false hazards, missed hazards and final obstacle clearance.

Land where intended, not merely somewhere on Mars

Land where intended, not merely somewhere on Mars
Delta-Sierra diagram: functional reading of the system.

Landing precision becomes infrastructure

For an early probe, a multi-kilometer ellipse may be acceptable. For a human base, missing the prepared zone can mean losing access to reserves, power, communications, or rescue vehicles. Landing accuracy becomes a logistics function.

Terrain Relative Navigation compares descent imagery with an onboard map to estimate position and select a reachable safe area. Perseverance demonstrated the principle on Mars, providing real heritage but at far lower mass than a human lander.

The hazard map is itself an assumption. Orbital resolution, dust, surface change, and georeferencing error can make an area less safe than advertised. Navigation integrity must therefore include confidence in the map.

A human site adds artificial hazards: old engine craters, dust deposits, antennas, cables, stores, habitats, and vehicles. The landing map must evolve with the town rather than remain frozen on the first sol.

Imagery, inertial sensing, radar, and altimetry must cross-check one another

A camera can lose contrast in dust or glare; an IMU drifts; radar can produce ambiguous returns over some terrain. Robust navigation comes from fusing sensors with different failure modes.

Error must be expressed as uncertainty, not just an estimated position. Two solutions 100 m from the same point are not equivalent if one is known to ±20 m and the other to ±300 m.

Divert logic must know the region actually reachable with remaining propellant. A safe site outside reach is not a solution; a slightly less favorable site within reach may be.

Integrity thresholds must be tied to action. If sensors stop agreeing, the question is not merely 'degraded navigation' but which maneuver remains safest at that instant of descent.

A safe site is not merely flat

Slope, rocks, craters, and local roughness matter for touchdown, but a human mission must also consider infrastructure distance, plumes, discarded hardware zones, and the ability to depart again.

The landing zone may need to be kilometers from the habitat to limit plume and accident hazards, turning landing error into surface-travel time. Every kilometer of error becomes rover energy, delay, and exposure.

A campaign of successive cargo landers requires repeatable geometry: each vehicle must land close enough to be useful but far enough not to damage earlier assets. Navigation and Martian urban planning meet here.

After each landing, surface observations can improve the map and change exclusion zones. The site becomes a living data product fed by rovers, possible aerial scouts, weather stations, and human inspection.

Treat landing error as a consumed resource

If a vehicle lands 2 km farther away and the recovery convoy consumes a defined 1.5 kWh per kilometer round trip per load unit, navigation error now has an explicit energy cost. The exact model depends on rover and terrain, but the logic connects accuracy to logistics.

Perseverance achieved a major reduction in landing ellipse through Range Trigger and TRN. A human system should not copy that target; allowable uncertainty must be recalculated from prepared-zone size, divert capability, and consequences of off-zone touchdown.

An error budget can include inertial navigation, mapping, image processing, latency, and control. Terms are not always independent; mishandled covariance can create artificially high confidence.

Failures that turn site selection into a real-time decision

A TRN camera saturated seconds before divert forces a decision on whether inertial/radar navigation is sufficient or a more conservative target is required.

A mismatch between map and terrain can indicate localization error or real site change. The algorithm must be able to reduce confidence rather than force a false match.

A very late hazard raises a dynamics question: the alternate area must be reachable without saturating propulsion or attitude control. Safety is constrained by what the vehicle can still physically do.

Finally, multiple landers require coordinated maps and reference frames. A shared-frame error can make individual systems internally correct while they refer to different physical points.

Seeing the ground is not enough: the lander must decide where it can still go

Perseverance demonstrated a chain, not merely a camera

Mars 2020 terrain-relative navigation linked functions that are often described separately: descent imagery, an onboard map, inertial estimation, landmark matching, position estimation, and selection of a safe target that remained reachable. Published Lander Vision System flight performance makes clear that the task is not simply recognizing a landscape. The vehicle must produce a coherent estimate quickly enough for guidance to still move the landing point.

Perseverance is valuable because it provides real Martian flight evidence. It cannot, however, be extrapolated without caution to a crewed lander. Mass, divert authority, plume-driven dust, propulsion response time, and base safety distances all change the reachable set. A target that is safe for a rover is not automatically acceptable for a vehicle of tens of tonnes.

Future architectures may add other sensors. Passive vision depends on illumination, terrain texture, and similarity between the stored map and the scene. Lidar or lidar-vision concepts aim to preserve localization and hazard detection in dust or low-contrast conditions. The objective is not to declare one sensor universally superior, but to build a chain whose failure modes are independent enough to avoid a common blind state.

Near a settlement, the hazard map becomes dynamic. A cargo pallet, disabled rover, construction site, plume-contaminated zone, or newly built habitat may appear after orbital maps were prepared. The lander should therefore combine a strategic map built well in advance with a recent local layer verified by surface assets. TRN then becomes part of a Martian traffic-management system.

A hazard map is a probability statement, not a coloured picture

Terrain-relative navigation must match what the camera sees to a prior map while the vehicle is moving, vibrating and changing illumination. A “safe” cell can still contain unresolved rocks or slope because map resolution and classification are finite. Guidance should therefore carry confidence in both localization and hazard classification.

Divert logic can then compare reachable sites using expected risk rather than a binary safe/unsafe flag. A slightly farther site with better map confidence may be preferable to a nearby site whose terrain classification is uncertain, provided propellant and time margins remain adequate.

Sources and references

Primary sources and specialist documentation

  1. JPL Robotics — Terrain Relative Navigation
  2. JPL — Mars 2020 landing mission overview
  3. NASA — Terrain Relative Navigation impact story
  4. NASA Science — Terrain Relative Navigation: Landing Between the Hazards
  5. JPL — Jezero hazard map
  6. JPL — LCAM heat-shield image and LVS description
  7. NASA NTRS — Assessment of M2020 Terrain Relative Landing Accuracy: Flight Performance vs Predicts
  8. NASA NTRS — The Lander Vision System for Mars 2020 Entry Descent and Landing
  9. NASA NTRS — Assessment of the Mars 2020 Entry, Descent, and Landing Simulation

Reference documents and exact scope

Documentary anchors used in this chapter