Entry, descent and landing: remove energy without losing the vehicle

Entry, descent and landing compresses aerothermodynamics, structures, guidance, navigation, propulsion and surface interaction into minutes. Mars atmosphere helps remove energy but also creates heat; parachutes work only inside an envelope; engines must remove what remains; navigation must select a reachable safe site. This module follows energy and margins rather than memorising a sequence.
1. Start with kinetic energy
Kinetic energy is Ek = ½mv², with mass m in kilograms, velocity v in m/s and energy in joules. A 10,000 kg vehicle at 5,500 m/s carries about 1.51 × 10¹¹ J of kinetic energy. The squared velocity term explains why entry is fundamentally an energy-management problem.
EDL begins as an energy problem. Kinetic energy is E_k = ½mv², so doubling velocity multiplies energy by four. A 20,000 kg vehicle at 5,500 m/s carries roughly 0.5 × 20,000 × 5,500² ≈ 3.0 × 10¹¹ joules, nearly 300 gigajoules. Not all of that becomes heat in the shield, but the scale shows what atmosphere, lift, parachutes and engines must remove or redirect. EDL is therefore best read as an energy-closure chain: after each phase, how much velocity remains, how much altitude remains and which system still has authority to remove the next part safely?
2. The entry corridor is an allowable region, not one line
Too steep an entry can drive heating and deceleration high; too shallow a trajectory may fail to remove enough energy or depart the intended region. Guidance manages uncertainty in atmosphere and initial state while remaining within an admissible corridor.
The entry corridor is the set of states that avoids two broad failures. Too steep, and deceleration and heating become concentrated; too shallow, and the vehicle may fail to dissipate enough energy, overshoot the target or skip back out. The corridor is not just one angle. Mass, ballistic coefficient, atmospheric density, lift, navigation uncertainty and thermal limits all change it. Martian weather uncertainty and state-estimation error consume margin before the vehicle even enters. A meaningful review therefore asks how much corridor width remains after dispersion and how guidance uses attitude or lift to stay inside that region rather than drawing one perfect nominal line.
3. Dynamic pressure connects density and speed to load
q = ½ρv², where q is dynamic pressure in pascals, ρ density in kg/m³ and v speed in m/s. Mars is thin, but velocity squared is powerful. Dynamic pressure helps explain structural load and deployment windows.
Exercise A — dynamic pressure
Use ρ = 0.010 kg/m³ and v = 1,000 m/s. Compute q.
q = 0.5 × 0.010 × 1,000² = 5,000 Pa = 5 kPa. This is a teaching point, not a full atmospheric state.
Dynamic pressure is q = ½ρv², where ρ is atmospheric density in kg/m³ and v is relative speed in m/s. It explains why a very thin atmosphere can still produce significant aerodynamic loads at hypersonic speed: velocity enters squared. Peak aerodynamic load does not necessarily occur at peak heating. The vehicle therefore crosses several different constraints in sequence—temperature, dynamic pressure, deceleration, stability and targeting accuracy. Altitude alone is not enough to identify the regime; actual density and speed matter. Guidance combines measurement and model to determine which part of the envelope the vehicle is really occupying.
4. Thermal protection manages heat flux and integrated exposure
Entry heating depends on trajectory, velocity, density and shape. Ablative materials intentionally transform and carry energy away. Reusable systems tolerate and redistribute heating. Peak temperature alone does not describe the problem; heat flux, duration and internal gradients matter.
Thermal protection manages both instantaneous heat flux and integrated exposure. A sharp peak lasting seconds and a lower flux lasting minutes can create different material responses. Convective-heating correlations often depend very strongly on velocity, making the early hypersonic phase especially important. Ablative systems deliberately consume material to carry energy away; reusable systems rely more on storage, conduction and radiation. A Mars design also has to include seams, geometry, dust and atmospheric uncertainty. After peak heating, stored energy can continue migrating into structure, so the thermal problem does not end at the instant the external flux starts to fall.
5. Parachutes have a deployment envelope
Mach number, dynamic pressure, canopy size, mass and structural load constrain when a parachute can deploy. The thin Martian atmosphere limits what parachutes can do for high mass. Heavy EDL therefore needs multiple braking mechanisms.
A parachute cannot be deployed at arbitrary speed or dynamic pressure. Its envelope depends on Mach number, density, load, diameter and vehicle dynamics. Mars combines high remaining speed with low density, which limits how much a parachute can do for a human-scale heavy payload. Inflation is itself a severe transient involving opening load, oscillation and possible interaction with the vehicle. A heavy architecture may use a parachute to remove part of the energy without asking it to complete the entire landing. The useful performance metric is therefore the altitude and velocity delivered to the powered phase that follows.
6. Retropropulsion removes the remaining velocity
Powered descent supplies impulse when aerodynamic braking is insufficient. For a 20,000 kg lander on Mars, weight is roughly 20,000 × 3.71 = 74.2 kN. Total thrust of 120 kN gives thrust-to-weight about 1.62 before guidance and margin demands.
Retropropulsion must generate enough thrust early enough to remove remaining velocity while preserving guidance margin. A simple constant-deceleration estimate gives stopping distance d ≈ v²/(2a). At 300 m/s with 10 m/s² net deceleration, the scale is about 4,500 m, before gravity variation, ignition delay or throttle constraints. The calculation shows why a few lost seconds or reduced thrust can consume altitude quickly. Heavy landers also face engine interaction with supersonic flow and later with the ground. Available thrust therefore has to be studied together with navigation, gimbal authority, plume effects and propellant reserve.
7. Terrain-relative navigation connects onboard images to maps
TRN can compare descent imagery with stored mapping to refine position and avoid hazards. Map resolution, lighting, dust and surface texture remain limitations. A robust system tracks confidence and knows when the visual solution should not be trusted.
Terrain-relative navigation compares onboard images or ranging data with a stored map to estimate position relative to hazards and the target. It becomes valuable when inertial navigation alone leaves an uncertainty ellipse too wide for the landing zone. TRN still depends on map quality, illumination, surface texture, altitude and available computation. A region that looks safe in a coarse map may be inadequately characterised for a very large vehicle. The solution needs a confidence measure and fallback logic. Correcting position is only useful if the lander still has enough divert capability to act on that new information.
8. A divert is useful only inside the reachable set
A safe site outside remaining time, thrust or propellant is not a real option. As altitude falls, the reachable set contracts. Guidance needs to rank safety and reachability together rather than pick the visually best location in isolation.
A divert trades altitude, velocity, time and propellant for a safer site. The reachable set shrinks throughout descent. At higher altitude a correction can be cheap but terrain knowledge is poorer; near the ground imagery is better but lateral authority is limited. The algorithm therefore compares hazard severity, site value, reserve and time. The geologically best location is not necessarily the safest landing location. For a crewed vehicle, the safe set also includes slope, bearing strength, plume clearance, crew egress and distance to pre-positioned infrastructure. Reachability is a physical constraint, not merely a ranking score.
9. Engine plumes change the last metres
Near the ground, exhaust erodes regolith and accelerates particles. It can obscure sensors, contaminate hardware and alter soil supporting the lander. Heavy vehicles need plume–surface interaction included in site design and stability verification.
Engine plumes become a coupled ground–vehicle problem during the final seconds. Jets can excavate soil, accelerate particles and create clouds that degrade cameras or ranging sensors. Debris may return toward engines, landing gear or nearby assets. The effect depends on thrust, height, engine count, jet angle and regolith properties. Design therefore separates vulnerable equipment, chooses tolerant engine geometry and assumes optical visibility can deteriorate just before contact. Robotic landing data is essential evidence, but the thrust scale of a human lander requires explicit qualification of extrapolation rather than pretending the environments are identical.
10. Failure scenario: inconsistent altitude sensing
If one altimeter becomes inconsistent, the estimator compares inertial propagation, velocity, other measurements and expected dynamics. The allowed response changes with phase. Early in descent there may be manoeuvre time; late in descent aggressive reconfiguration can be more dangerous. FDIR therefore needs phase-aware confidence rules.
Inconsistent altitude sensing should not be solved by a simple average. Radar, lidar, inertial navigation and terrain-relative navigation may measure different quantities with different delays and geometries. FDIR compares each observation with vertical velocity, expected terrain and time history. If radar reports 800 m while lidar and terrain matching converge near 650 m, the decision depends on confidence and physical consistency, not just sensor count. The degraded mode must define which source may trigger ignition, how much extra altitude margin is required and when the vehicle should abandon an aggressive target in favour of a more conservative profile or site.
Guided case — altitude margin and ignition decision
Consider a lander descending at 250 m/s when powered descent becomes available. With an average net deceleration of 12 m/s², the ideal stopping distance v²/(2a) is about 2,604 m. Adding a two-second ignition delay consumes roughly another 500 m at first order, before including gravity and thrust buildup. The comparison shows why altitude sensing, command latency and engine-start transient belong to the same margin budget.
Students then add dispersion: actual net deceleration between 10 and 12 m/s² and estimated altitude with ±80 m uncertainty. Ignition should not be planned from the average if the conservative case fails to close. Margin comes from the combined uncertainty and from a decision altitude that still preserves a fallback.
Finally, a hazardous patch is detected after ignition. Divert is accepted only if lateral reserve does not destroy vertical closure. EDL becomes a simultaneous trade among terrain safety, remaining velocity, altitude and propellant rather than a sequence of independent subsystems.
11. Mini-project: close an EDL chain
- Choose teaching values for entry mass and speed.
- Compute kinetic energy.
- Assign energy removal to atmosphere, parachute and propulsion qualitatively.
- List navigation measurements.
- Add a hazard and divert.
- Remove one sensor in terminal descent.
- State success criteria after touchdown.
The answer should trace energy, state knowledge and control margin to the surface.
12. Mission lab — track energy closure through powered descent
Take a teaching vehicle of 20,000 kg entering powered descent at 250 m/s. Its kinetic energy is E = ½mv² = 0.5 × 20,000 × 250² = 625 MJ. Propulsion must remove this motion while also supporting gravity and preserving guidance authority. Energy does not directly give propellant mass because the engine acts through thrust, exhaust velocity and trajectory, but it provides a powerful scale check.
Altitude and time must close at the same time. If vertical speed were 50 m/s for ten seconds, the simple displacement scale would be Δh = v × Δt = 500 m. Real descent is accelerated and guided, yet this mental check immediately reveals whether a proposed sensor delay or manoeuvre can fit inside remaining altitude.
Margin is temporal as well as propulsive. A late hazard detection can leave substantial propellant but insufficient time to move laterally, settle the new trajectory and verify the landing point. Terminal displays therefore need state, confidence, thrust reserve and the remaining reachable set—not just a green/red hazard flag.
Another useful check is thrust-to-weight. If the same 20,000 kg lander has 120 kN total thrust, Mars weight is about 74.2 kN and the ratio is about 1.62. Part of that authority supports the vehicle against gravity; the remainder must provide deceleration and lateral control. Engine-out cases should recompute the ratio rather than assume “multiple engines” guarantees control.
13. Limits of robotic evidence for a heavy human lander
Robotic Mars missions provide extraordinary evidence for navigation, thermal protection, parachutes and surface operations. They do not automatically qualify a vehicle tens of tonnes in mass. Physics scales continuously, but propulsion geometry, plume interaction, structural energy and consequence of error change.
A mature evidence ladder distinguishes what has flown on Mars, what has been demonstrated in representative Earth testing, what has been simulated with validated models and what remains an architecture concept. This prevents a technology success from being silently promoted into proof of a much larger integrated system.
For a design review, identify the largest scale jump in each subsystem: heat shield, parachute or other decelerator, engines, landing gear, TRN, plume interaction and site infrastructure. Then ask what test or flight closes that gap. The unanswered questions become a development roadmap rather than hidden uncertainty.
Sources and references
Verified primary supplement: NASA NTRS — Rocket Plume Interactions for NASA Landing Systems
Engineering studio — propagate an EDL dispersion
The case imposes both atmospheric density 15% below prediction and vehicle mass 2% above prediction. Ballistic coefficient β = m/(Cd·A) therefore rises at least with mass, while dynamic pressure q = ½ρv² falls directly with density at equal speed. The student explains the consequence: aerodynamic deceleration develops differently and more energy may reach the propulsive phases.
The exercise then propagates this dispersion toward terminal propellant reserve without pretending to run a high-fidelity simulation. Reasoning must identify flight-observable variables, the point at which atmospheric estimation can be updated, thresholds that make the intended site unreachable, and the choice of a diversion zone. EDL becomes a connected decision chain rather than a catalogue of technologies.
The EDL capstone closes with a reachability question. A landing site is acceptable only while the vehicle can still divert to a safe point after accounting for state-estimation error and propellant reserve. The student therefore separates geometric reach from certified reach: the latter is smaller because it must contain uncertainty, control authority and a terminal reserve that remains usable after the diversion.
The acceptance log also keeps the predicted and measured state at each transition, allowing later review to separate atmospheric dispersion from guidance or propulsion error.