Owen Pavlock.
← All projects

Reefed Parachute & Tether Shock Loads

One canopy instead of three, and the analysis and testing needed to show the recovery hardware survives the loads of opening.

TeamMichigan Aeronautical Science Association
RoleChutes & Tethers Responsible Engineer, Recovery
TimelineAug 2025 to present
ToolsMATLAB, C++, NASA Trick & JEOD, Linux

01 / CONTEXT

What a responsible engineer owns

MASA is Michigan's student rocketry team, building large liquid-fueled rockets. On the recovery subteam I'm the responsible engineer for parachutes and tethers. That means I own the design, the analysis, and the verification evidence that those parts will survive flight, and I present it for flight certification.

Two problems sit on my plate. The current recovery system uses three separate parachutes, and every extra parachute adds another deployment event, another set of hardware, and another way to fail. And every load path, from the canopy through the shroud lines and bridle to the rocket, needs evidence that it won't break when the parachute snaps open.

02 / CONCEPT

One canopy that opens twice

A skirt-reefed parachute has a line threaded around its skirt that holds the canopy partly closed. Reefed to a small diameter, the main parachute can come out at apogee and act as the drogue for most of the descent, falling fast enough to limit drift. Near the ground, a line cutter severs the reefing line and the canopy opens fully for a soft landing.

That turns three parachutes into one. The tradeoff is that the second opening happens at speed with a big canopy, so the disreef shock becomes the load case that sizes everything downstream.

Diagram: the main canopy reefed to 7 feet with a reefing line and cutter at the skirt, then fully open to 24 feet after disreef
Fig. 1The canopy is a 24 ft (288 in) toroidal design with a roughly 40 in spill hole, reefed to a 7 ft drogue-equivalent diameter. The model compares a skirt-mounted cutter (fires instantly) with a nose-cone cutter that pulls the line through a lanyard (an estimated 0.15 s delay).

03 / ANALYSIS

Predicting the opening shock

I built the opening-shock model in MATLAB from the methods in Knacke's Parachute Recovery Systems Design Manual, starting from a teammate's single-stage main parachute script and extending it to a two-stage reefed opening. Each opening uses Knacke's fill-time relation, which scales with canopy diameter and the speed at line stretch, and steps the equations of motion for the rocket under the growing drag area.

fill time      t_f = n · D / v^0.85
drag area      (C_D·S)(t) grows from η·S_reefed to S_full over t_f
motion         m · dv/dt = m·g − ½ ρ v² (C_D·S)(t)
reefed hold    integrate until altitude = disreef altitude, then cut

To keep it fast, the solver uses a 0.1 ms step during the two opening transients, where the load spikes, and a 10 ms step for the long reefed descent between them. The disreef is triggered by altitude rather than a timer, the way a dual-deploy altimeter would fire it.

  • Rocket mass383 lbm
  • Apogee / deployment10,000 ft
  • Canopy, full open24 ft, CD 2.2
  • Reefed diameter7 ft
  • Disreef altitude1,000 ft
  • Bridle rating5,000 lb
  • Shroud lines24 × 250 lb
  • Ejection velocity20 ft/s
altitude, thousand ft02468100s20s40s60s80s100s120sdisreef at 1,000 ft
Fig. 2Simulated descent. The reefed canopy brings the rocket from 10,000 ft to the disreef altitude in about 119 s, entering disreef at about 71 ft/s.
lbf04008001,2001,600A · REEFED DEPLOY, FROM APOGEE384 lbf0s5s10s15sB · DISREEF TO FULL OPEN, FROM CUT1,490 lbf0s1s2s3s
Fig. 3Finite-mass opening shock for both events. Disreef is the governing load at 1,490 lbf, about four times the reefed deployment.
1,490
lbf peak shock, at disreef
3.4×
margin on the 5,000 lb bridle
62 lbf
per shroud line, 4.0× margin

This is a first look, not a certified number. A few inputs are still placeholders, including the fill constant and opening-force coefficient (taken from flat-circular canopy values until toroidal values are confirmed) and the apogee and disreef altitudes. The model is set up so those can be swapped in as the design firms up.

04 / VERIFICATION

A tether test to 4,000 lbf

Analysis alone doesn't certify hardware, so I'm leading a shock-load verification test on the parachute and tether. The tricky part is predicting what the heavy drop will do before running it, so the test can be set up safely and the result has something to be checked against.

The plan uses two drops. A light drop with a known mass and drop height calibrates the tether's stiffness. Setting the potential energy lost equal to the spring energy at maximum stretch gives the stiffness directly. That stiffness then predicts the heavy drop: how far the tether stretches, whether the load reaches the ground, and when.

calibrate     k = 2·m_L·g·(h + y_L) / y_L²
heavy drop    v₀ = √(2·g·H)
max stretch   y_max = [m_H·g + √((m_H·g)² + 2·k·m_H·g·H)] / k
ground check  L + y_max ≥ H_ground ?
motion        y(t) = δ(1 − cos ωt) + (v₀/ω)·sin ωt,   ω = √(k/m_H)

The script checks whether the stretched tether reaches the ground. If it does, it solves the motion equation for the time and speed at impact and the time spent on the ground versus in the air, which sets up the test fixture and the safety zone. The MATLAB model of the full parachute and tether system then predicts the response to verify structural integrity to 4,000 lbf for flight certification.

05 / SIMULATION

A 6-DOF flight simulator

Recovery loads depend on the state the rocket is in when the parachute comes out, so the team needs a full flight simulation. I'm building a six-degree-of-freedom simulator in C++ on NASA's Trick simulation framework and the JEOD orbital-dynamics package, running on Linux.

Most of the work so far is architecture: how Trick schedules jobs, how the integration loop advances the state, and how physics models (thrust, aerodynamics, mass properties, gravity) plug in. The goal is a structure that handles more than one rocket configuration, so a new vehicle is a new set of models rather than a new simulator.

  • Job schedulingSeparating what runs every integration step from what runs at a slower rate or only on events like burnout and deployment.
  • Integration loopAdvancing translational and rotational state together with a consistent time step across models.
  • Physics modelsThrust, aerodynamics, changing mass properties, and gravity as interchangeable modules.
  • ConfigurationsVehicle-specific data kept out of the core so multiple rockets share one simulator.