Attack address acquisition method and circuit, hammer refresh method and memory

By receiving activation row address information in a semiconductor memory, updating a count value and latching an address, and randomly selecting an attack address for hammer refresh, the row hammering problem is solved and the reliability and security of the memory are improved.

CN115249499BActive Publication Date: 2025-09-05CHANGXIN MEMORY TECH INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110466937.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-04-28
Publication Date
2025-09-05
Estimated Expiration
2041-04-28

AI Technical Summary

Technical Problem

As semiconductor memory shrinks in size, the distance between adjacent rows narrows, resulting in an increased risk of row hammering problems, which affects memory reliability.

Method used

By receiving the activation row address information, updating the activation count value, generating a comparison signal to latch the activation row address, and randomly selecting one of the multiple activation row addresses as the attack address, the adjacent row is determined to be hammer refreshed.

Benefits of technology

Effectively reduce the risk of row hammering, improve the data reliability and security of storage, and reduce the risk of malicious cracking and targeted attacks on acquisition methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115249499B_ABST
    Figure CN115249499B_ABST
Patent Text Reader

Abstract

The embodiments of the present application relate to a method for acquiring an attack address, a circuit thereof, a hammer refresh method, and a memory. The method for acquiring an attack address comprises: receiving an activation signal carrying activation row address information, and updating an activation count value corresponding to the activation row address according to a first preset order; generating a hit signal when the activation count value meets a preset condition; latching the activation row address according to the hit signal; and randomly selecting at least one of the latched activation row addresses as an attack address. In the embodiments of the present application, by randomly selecting one of the multiple candidate activation row addresses as the attack address, the risk of the acquisition method being maliciously cracked and targeted by attacks can be effectively reduced, thereby further improving the security of the acquisition method. That is, the embodiments of the present application provide an acquisition method with high reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of semiconductor memory technology, and in particular to a method for obtaining an attack address and a circuit thereof, a hammer refresh method, and a memory. Background Art

[0002] With the continuous advancement of semiconductor memory technology, the size of Synchronous Dynamic Random Access Memory (SDRAM) continues to shrink. However, as memory size shrinks, the distance between adjacent rows also shrinks, leading to an increasing risk of row hammering. Row hammering occurs when repeated accesses to an aggressive row within a certain period of time cause adjacent victim rows to fail. Row hammering can cause data in the victim row to change, significantly reducing memory reliability. Summary of the Invention

[0003] The embodiments of the present application provide a method for obtaining an attack address and a circuit thereof, a hammer refresh method, and a memory, which can effectively reduce the risk of row hammering, thereby improving the data reliability of the memory.

[0004] A method for obtaining an attack address, comprising:

[0005] receiving an activation signal carrying activation row address information, and updating an activation count value corresponding to the activation row address according to a first preset order;

[0006] When the activation count value meets a preset condition, a hit signal is generated;

[0007] latching the active row address in response to the match signal;

[0008] At least one of the latched active row addresses is randomly selected as the attack address.

[0009] In one embodiment, when the activation count value satisfies a preset condition, generating a hit signal includes:

[0010] When the activation count value is equal to the comparison signal count value, generating the comparison signal;

[0011] The acquisition method further includes: in response to the matching signal, updating the matching signal count value according to a second preset order.

[0012] In one embodiment, the randomly selecting at least one of the latched active row addresses as the attack address comprises:

[0013] In response to a refresh signal, at least one of the latched active row addresses is randomly selected as the attack address.

[0014] In one embodiment, the method further comprises:

[0015] In response to the match signal, the activation count value corresponding to each of the attack addresses is reset.

[0016] In one embodiment, updating the activation count values ​​corresponding to the activation row addresses according to the first preset order includes: updating the activation count values ​​corresponding to the activation row addresses in ascending order of values;

[0017] The resetting the activation count value corresponding to each of the attack addresses includes: clearing the activation count value corresponding to each of the attack addresses to zero.

[0018] In one embodiment, updating the activation count value corresponding to the activation row address according to the first preset order includes:

[0019] The activation count value is updated according to a current activation count value corresponding to the activation row address and a first preset counting step.

[0020] In one embodiment, in response to the matching signal, updating the matching signal count value according to a second predetermined order includes:

[0021] The matching signal count value is updated according to the current matching signal count value and a second preset counting step.

[0022] In one embodiment, the first preset counting step size is equal to the second preset counting step size.

[0023] A hammer refresh method includes the steps of the above-mentioned method for obtaining the attack address, and further includes:

[0024] Determining that an adjacent row address of the attack address is a hammer refresh address;

[0025] Perform hammer refresh on the data row corresponding to the hammer refresh address.

[0026] In one embodiment, determining that the adjacent row address of the attack address is a hammer refresh address includes:

[0027] A first adjacent row address and a second adjacent row address of the attack address are respectively obtained, where the attack address is located between the first adjacent row address and the second adjacent row address.

[0028] A circuit for obtaining an attack address, comprising:

[0029] an activation counter, configured to receive an activation signal carrying activation row address information and update an activation count value corresponding to the activation row address according to a first preset order;

[0030] a count comparison unit connected to the activation counter, and configured to generate a match signal when the activation count value satisfies a preset condition;

[0031] An address latch connected to the counting and comparing unit, and configured to latch the active row address in response to the matching signal;

[0032] The random selection unit is connected to the address latch and is used to randomly select at least one of the latched multiple active row addresses as the attack address.

[0033] In one embodiment, it further includes:

[0034] A sequence counter is configured to update the hit signal count value according to a second preset order in response to the hit signal. The sequence counter is connected to the count comparison unit to output the hit signal count value to the count comparison unit and to update the hit signal count value in response to the hit signal, thereby achieving flexible latching of the activated row address. The sequence counter has a built-in second preset order for value updates, and the initial value of the second preset order can be set as needed to reduce the risk of malicious cracking and targeted attacks on the acquisition method.

[0035] In one embodiment, the counting and comparing unit includes:

[0036] The numerical comparator is connected to the activation counter and the sequence counter respectively, and is used to generate the matching signal when the activation count value is equal to the matching signal count value.

[0037] In one embodiment, the random selection unit includes:

[0038] a random number generator, configured to generate a random number, wherein the random number is less than or equal to the number of activated row addresses stored in the address latch;

[0039] A multiplexer is connected to the random number generator and the address latch respectively, and is used to select the activation row address in the order corresponding to the random number as the attack address.

[0040] A memory includes the attack address acquisition circuit as described above.

[0041] The above-mentioned attack address acquisition method and its circuit, hammer refresh method and memory, the attack address acquisition method includes: receiving an activation signal carrying activation row address information, updating the activation count value corresponding to the activation row address according to a first preset order; when the activation count value meets a preset condition, generating a hit signal; in response to the hit signal, latching the activation row address; randomly selecting at least one of the multiple latched activation row addresses as the attack address. In the embodiment of the present application, by obtaining the activation count value of each row in the storage array, the probability of row hammering problems occurring in each data row can be accurately evaluated, which facilitates the memory to execute corresponding row hammering avoidance measures according to different occurrence probabilities. Moreover, by randomly selecting one of the multiple alternative activation row addresses as the attack address, the risk of the acquisition method being maliciously cracked and targeted by attacks can be effectively reduced, thereby further improving the security of the acquisition method. That is, the embodiment of the present application provides an attack address acquisition method with high reliability. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0043] Figure 1 This is one of the structural block diagrams of a circuit for acquiring an attack address according to one embodiment;

[0044] Figure 2 This is a flowchart of a method for obtaining an attack address according to an embodiment;

[0045] Figure 3 This is a second flowchart of a method for obtaining an attack address according to an embodiment;

[0046] Figure 4 This is a third flowchart of a method for obtaining an attack address according to an embodiment;

[0047] Figure 5 This is a fourth flowchart of a method for obtaining an attack address according to an embodiment;

[0048] Figure 6 This is a fifth flowchart of a method for obtaining an attack address according to an embodiment;

[0049] Figure 7 A flowchart of a hammer refresh method according to an embodiment;

[0050] Figure 8 is a schematic diagram of an attack row and adjacent rows according to an embodiment;

[0051] Figure 9 This is a second structural block diagram of a circuit for acquiring an attack address according to an embodiment;

[0052] Figure 10 This is the third structural block diagram of the attack address acquisition circuit according to one embodiment.

[0053] Component number description:

[0054] Activation counter: 100; count comparison unit: 200; value comparator: 210; address latch: 300; random selection unit: 400; random number generator: 410; multiplexer: 420; sequence counter: 500. DETAILED DESCRIPTION

[0055] To facilitate understanding of the embodiments of the present application, a more comprehensive description of the embodiments of the present application will be provided below with reference to the accompanying drawings. The accompanying drawings provide preferred embodiments of the embodiments of the present application. However, the embodiments of the present application can be implemented in many different forms and are not limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and comprehensive disclosure of the embodiments of the present application.

[0056] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art in the art of the present application. The terms used herein in the description of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. The term "and / or" as used herein includes any and all combinations of one or more of the relevant listed items.

[0057] The embodiment of the present application provides a method for obtaining an attack address. The method of the embodiment of the present application is applied to Figure 1 The attack address acquisition circuit shown in FIG. 1 is used as an example for explanation. Specifically, the attack address acquisition circuit and the storage array of the embodiment of the present application are both arranged inside the memory and are interconnected. The attack address acquisition circuit is used to determine the data rows (i.e., attack addresses) in the storage array that are frequently read and written, so as to facilitate the implementation of corresponding countermeasures to avoid data anomalies or loss caused by row hammering. Among them, the corresponding countermeasures include but are not limited to refreshing the stored data in the rows adjacent to the attack address, limiting the data read and write operations on the attack address, etc.

[0058] The memory is also provided with a command decoder, which obtains command signals from the controller and decodes the command signals to obtain various internal instruction signals that can be executed by the internal circuit, such as the activation signal ACT, the pre-charge signal Pre, the read / write signal R / W, and the refresh signal REF. The attack address acquisition circuit receives the activation signal ACT and the refresh signal REF, and executes each step in the attack address acquisition method in response to the above signals.

[0059] The activation signal ACT is activated when the controller instructs the memory to perform a row access. When the activation signal ACT is activated, the data row in the memory array that needs to be read or written is opened. The read / write signal R / W is activated after the data row that needs to be read or written is opened. When the read / write signal R / W is activated, data can be read or written to the corresponding data row. The precharge signal Pre is activated after the read / write operation on the data row is completed. When the precharge signal Pre is activated, the data row in the memory array that needs to be read or written is closed.

[0060] The refresh signal REF is activated when an automatic refresh command needs to be executed, and can be repeatedly activated at a certain period according to the internal timing. It is understandable that even if there is no row hammering problem, the charge stored in the storage capacitor of the memory cell will continue to be lost over time. Therefore, the memory needs to perform a refresh operation at a certain period to ensure the accuracy of the data stored in the memory cell. Specifically, when performing a refresh operation, the current charge amount in the memory cell is first obtained, and then the data stored in the memory cell is judged to be 1 or 0 based on the current charge amount. Finally, the storage capacitor is recharged or discharged based on the judgment result, so that the charge stored in the storage capacitor corresponds to the data to be stored.

[0061] refer to Figure 1 The attack address acquisition circuit of the embodiment of the present application includes an activation counter 100, a count comparison unit 200, an address latch 300, and a random selection unit 400. Each step of the acquisition method of the embodiment of the present application is executed one-to-one by each component in the acquisition circuit. Figure 2 This is a flowchart of a method for obtaining an attack address according to an embodiment of the present invention, with reference to Figure 1 and Figure 2 The acquisition method of this embodiment includes steps S100 to S400.

[0062] S100: receiving an activation signal carrying activation row address information, and updating an activation count value corresponding to the activation row address according to a first preset order.

[0063] The activation row address refers to the activation row address carried by the activation signal received when the activation counter 100 is updated. In other words, the activation signal is used to activate the data row corresponding to the activation row address. Specifically, the activation counter 100 has a built-in first preset order for value updates. The first preset order may be, for example, X1, X2, X3, X4…. If the activation count value of the activation counter 100 is X2 before receiving the activation signal for the current cycle, then after receiving the activation signal for the current cycle, the activation count value of the activation counter 100 is updated to X3. Optionally, the first preset order may be an increasing sequence with a fixed change pattern, such as 11, 12, 13, 14…. The first preset order may also be a decreasing sequence with a fixed change pattern, such as 18, 16, 14, 12…. The first preset order may also be a series of sequences with no fixed change pattern, such as 11, 13, 14, 15, 17…. It should be clarified that this embodiment does not specifically limit the setting method of the first preset order. It only requires that the first preset order is a finite length sequence, and the activation counter 100 can update the activation count value once according to the first preset order each time it receives an activation signal. That is, other counters with regular changes except random counters can be identified as the activation counter 100 of this embodiment.

[0064] S200: When the activation count value meets a preset condition, a matching signal is generated.

[0065] Among them, the hit signal refers to the enable signal used to select the activation row address through comparison. Specifically, when the activation count value meets certain preset conditions, the count comparison unit 200 may consider that the data row corresponding to the activation counter 100 is frequently activated and there is a risk of row hammering, that is, a hit signal may be issued to instruct the address latch 300 to latch the address of the data row corresponding to the activation counter 100 (i.e., the activation row address). Exemplarily, a number threshold may be pre-configured in the count comparison unit 200, and when the activation count value reaches the number threshold, a corresponding hit signal may be generated. It is understandable that this embodiment does not specifically limit the type of the count comparison unit 200. The count comparison unit 200 may also be a comparator with more complex data processing or logic judgment rules, rather than just for comparing the size relationship of numerical values, thereby improving the complexity of the attack address acquisition method and acquisition circuit, thereby reducing the risk of malicious hacking and improving the reliability of the memory.

[0066] S300: In response to the matching signal, latch the active row address.

[0067] Specifically, the address latch 300 latches the active row address in response to the hit signal. The latched active row address can be used as a candidate address for the attack address. The address latch 300 can latch multiple active row addresses. Optionally, the address latch 300 can output all latched active row addresses as attack addresses when needed, or can output only a portion of the latched active row addresses as attack addresses. The number of attack addresses can be determined based on parameters such as refresh rate.

[0068] S400: Randomly select at least one of the latched active row addresses as the attack address.

[0069] The random selection unit 400 can generate at least one random number at a preset time interval, and the numerical range of the generated random number corresponds to the number of addresses that the address latch 300 can latch. The preset time interval can be determined by an external clock signal. For example, if the address latch 300 can latch 10 active row addresses, the random number generated by the random selection unit 400 can be any integer between 1 and 10. The random selection unit 400 then selects and outputs an active row address in the corresponding order based on the generated random number as the attack address.

[0070] In this embodiment, the method for acquiring the attack address includes: receiving an activation signal carrying activation row address information, and updating the activation count value corresponding to the activation row address according to a first preset order; when the activation count value meets a preset condition, generating a hit signal; in response to the hit signal, latching the activation row address; and randomly selecting at least one of the multiple latched activation row addresses as the attack address. In the embodiment of the present application, by acquiring the activation count value of each row in the storage array, the probability of occurrence of row hammering problems in each data row can be accurately assessed, so that the memory can execute corresponding row hammering avoidance measures according to different occurrence probabilities. Moreover, by randomly selecting one of the multiple alternative activation row addresses as the attack address, the risk of the acquisition method being maliciously cracked and targeted by attacks can be effectively reduced, thereby further improving the security of the acquisition method. That is, the embodiment of the present application provides an acquisition method with high reliability.

[0071] In one embodiment, a plurality of activation counters 100 are provided in the memory, and each activation counter 100 corresponds to at least one data row to count the number of activations of the corresponding data row. It will be appreciated that the memory includes a large number of storage cells, and accordingly, a large number of data rows. Maintaining statistics on the number of activations for each data row would consume a significant amount of time and space. Therefore, the activation counter 100 can be configured with a corresponding activation count list, and the activation count list only stores the activation counts for data rows with a high number of activations. In other words, the data rows stored in the activation count list are those with a higher risk of row hammering, thereby reducing the amount of data that needs to be stored.

[0072] Furthermore, the activation signal can be sampled at a preset frequency. For example, the attack address acquisition circuit can sample one of the activation signals every time it receives n activation signals, and obtain the activation row address information carried by the activation signal for statistics, without counting the remaining n-1 activation signals. It is understandable that if a data row is frequently activated, then when sampling is performed at a fixed interval, the number of activations of the data row is also much greater than the number of activations of other normally read and written data rows. Therefore, this is also a more reliable counting method for the activation counter 100, and can greatly reduce the number of counts of the activation counter 100, thereby effectively reducing the counting pressure of the activation counter 100 and reducing the time required for the attack address acquisition method, thereby improving the efficiency of the attack address acquisition method.

[0073] Figure 3 This is a second flow chart of a method for obtaining an attack address according to an embodiment, referring to Figure 3 In this embodiment, the method for obtaining the attack address includes steps S100 to S400.

[0074] S100: receiving an activation signal carrying activation row address information, and updating an activation count value corresponding to the activation row address according to a first preset order.

[0075] S210: When the activation count value is equal to the comparison signal count value, generate the comparison signal.

[0076] S300: In response to the matching signal, latch the active row address.

[0077] S510: In response to the matching signal, update the matching signal count value according to a second preset order.

[0078] S400: Randomly select at least one of the latched active row addresses as the attack address.

[0079] Among them, steps S100, S300 to S400 and Figure 2 The embodiments are the same, so reference may be made to the aforementioned embodiments, which will not be described in detail here. Specifically, the second preset order may be, for example, Y1, Y2, Y3, Y4… If the count value of the match signal is Y2 before the match signal is received, the count value of the match signal is updated to Y3 after the match signal is received. Similar to the first preset order, the second preset order may be an increasing sequence with a fixed change rule, a decreasing sequence with a fixed change rule, or a series of sequences without a fixed change rule. It should be noted that the first preset order may be the same as the second preset order, or may be different from the first preset order, and this embodiment does not specifically limit this. In this embodiment, the sequence counter updates the count value of the match signal in response to the match signal. By adopting a match signal count value that is continuously updated based on the match signal, the risk of the acquisition method being maliciously cracked and targetedly attacked can be effectively reduced, thereby improving the security of the acquisition method.

[0080] In one embodiment, the randomly selecting at least one of the multiple latched active row addresses as the attack address includes randomly selecting at least one of the multiple latched active row addresses as the attack address in response to the refresh signal. Specifically, as described above, the refresh signal output by the controller is used to control the memory to automatically refresh. Automatic refresh refers to the aforementioned refresh method used to avoid the problem of charge loss caused by time. In this embodiment, the address latch 300 outputs the attack address in response to the refresh signal, so that corresponding operations can be performed on the attack address simultaneously during the automatic refresh phase of the memory, thereby improving the processing efficiency of the corresponding operations and avoiding affecting the operating performance of the memory.

[0081] Furthermore, the frequency at which random selector 400 receives refresh signals is lower than the frequency at which activation counter 100 receives activation signals, but there is a positive correlation between the reception frequencies of the two signals. It is understood that the frequency with which data rows are activated in response to activation signals is generally positively correlated with the read and write speed of the memory. Furthermore, it is precisely the constant reading and writing of the attacked data rows that increases the risk of row hammering. Therefore, setting the controller's refresh signal frequency based on the frequency of data row activation can better protect the memory array.

[0082] Specifically, the example of a hammer refresh operation based on the attack address is used for explanation. First, the automatic refresh operation can refresh multiple data rows that need to be refreshed in response to a single refresh signal. The automatic refresh operation requires the row refresh cycle (tRFC), and there is an average refresh interval of the refresh interval time (tREFI) between automatic refresh operations. In response to the refresh command, the memory performs automatic refresh on multiple data rows. It can be understood that in this embodiment, because the number of attack addresses is generally less than the number of addresses that need to be automatically refreshed, the time required for hammer refresh is generally shorter than the row refresh cycle time tRFC. That is, the row refresh cycle time tRFC is sufficient to complete the hammer refresh. Therefore, the hammer refresh operation of this embodiment does not occupy the data read and write time of the memory cells corresponding to the adjacent rows of the attack address, and can also effectively enhance the data security of the memory, that is, provide a method with high reliability and efficiency.

[0083] The number of attack addresses outputted can be one or more, for example, two or four. It is understood that if the wiring density in the memory is high, which means the risk of row hammering is greater, then hammering refresh can be performed on a larger number of data rows at a time. If the wiring density in the memory is low, then hammering refresh can be performed on a smaller number of data rows at a time. Therefore, the specific number can be determined based on the wiring density in the memory and is not specifically limited in this embodiment.

[0084] Figure 4 This is a flowchart of a method for obtaining an attack address according to an embodiment of the present invention. Figure 4 In this embodiment, the method for obtaining the attack address includes steps S100 to S410.

[0085] S100: receiving an activation signal carrying activation row address information, and updating an activation count value corresponding to the activation row address according to a first preset order.

[0086] S210: When the activation count value is equal to the comparison signal count value, generate the comparison signal.

[0087] S300: In response to the matching signal, latch the active row address.

[0088] S510: In response to the matching signal, update the matching signal count value according to a second preset order.

[0089] S520: Responding to the match signal, resetting the activation count value corresponding to each of the attack addresses.

[0090] S410: In response to a refresh signal, randomly select at least one of a plurality of latched active row addresses as the attack address.

[0091] In this embodiment, latching the activation row address in step S300, updating the comparison signal count value according to the second preset order in step S510, and resetting the activation count value corresponding to each attack address in step S520 are performed in response to the same refresh signal. By setting them to be executed in response to the same signal, the synchronization of the above three steps can be effectively improved, and the number of signals required for the attack address acquisition method can be reduced, thereby simplifying the logic of the acquisition method.

[0092] It is understandable that the execution entities of the above three steps are not the same. Specifically, the address latch 300 latches the activation row address, the sequence counter updates the hit signal count value according to the second preset order, and the activation counter 100 resets the activation count value corresponding to each attack address. Therefore, the embodiment of the present application does not specifically limit the execution order of the above three steps, that is, the hit signal can first indicate the execution of one of the steps, and after the step is completed, it indicates the execution of another step. This embodiment does not need to limit the execution order between the steps. Exemplarily, the execution order of the above three steps can be set by adding a delay unit in the circuit. It is understandable that the above three steps can also be executed simultaneously to improve the data processing and reset efficiency of the acquisition method of the attack circuit.

[0093] Figure 5 This is a fourth flow chart of a method for obtaining an attack address according to an embodiment of the present invention. Figure 5 In this embodiment, the method for obtaining the attack address includes steps S110 to S410.

[0094] S110: Receive an activation signal carrying activation row address information, and update the activation count value corresponding to the activation row address in ascending order.

[0095] S210: When the activation count value is equal to the comparison signal count value, generate the comparison signal.

[0096] S300: In response to the matching signal, latch the active row address.

[0097] S510: In response to the matching signal, update the matching signal count value according to a second preset order.

[0098] S521: In response to the match signal, clear the activation count value corresponding to each of the attack addresses.

[0099] S410: In response to a refresh signal, randomly select at least one of a plurality of latched active row addresses as the attack address.

[0100] In this embodiment, the updating of the activation count values ​​corresponding to the activation row addresses according to the first preset order in step S100 specifically includes updating the activation count values ​​corresponding to the activation row addresses in ascending order of values. The resetting of the activation count values ​​corresponding to each of the attack addresses in step S520 specifically includes clearing the activation count values ​​corresponding to each of the attack addresses to zero.

[0101] Specifically, this embodiment updates the activation count value in an incrementing manner, for example, by updating the activation count value in a manner of 0, 1, 2, 3, etc. Accordingly, the activation counter 100 is reset to zero. The two have a clear correspondence, greatly simplifying the difficulty of analyzing the data of the activation counter 100, thereby improving the data processing efficiency of the acquisition method of this embodiment. In other embodiments, if the activation count value is updated in a decrementing manner, for example, by updating the activation count value in a manner of 10, 9, 8, 7, etc. , the activation counter 100 can be reset to 10 accordingly, thereby achieving the aforementioned effect of improving data processing efficiency.

[0102] Figure 6 This is a flowchart of a method for obtaining an attack address according to an embodiment of the present invention. Figure 6 In this embodiment, the method for obtaining the attack address includes steps S120 to S410.

[0103] S120: Receive an activation signal carrying activation row address information, and update the activation count value according to a current activation count value corresponding to the activation row address and a first preset counting step.

[0104] S210: When the activation count value is equal to the comparison signal count value, generate the comparison signal.

[0105] S300: In response to the matching signal, latch the active row address.

[0106] S511 : In response to the matching signal, update the matching signal count value according to the current matching signal count value and a second preset counting step.

[0107] S521: In response to the match signal, clear the activation count value corresponding to each of the attack addresses.

[0108] S410: In response to a refresh signal, randomly select at least one of a plurality of latched active row addresses as the attack address.

[0109] In this embodiment, the updating of the activation count value corresponding to the activation row address according to the first preset order in step S100 specifically includes updating the activation count value according to the current activation count value corresponding to the activation row address and the first preset counting step. The updating of the comparison signal count value according to the second preset order in step S510 specifically includes updating the comparison signal count value according to the current comparison signal count value and the second preset counting step.

[0110] Among them, when the first preset counting step and the second preset counting step are both greater than 0, it is considered that step S210 in the aforementioned embodiment is updated in the order of increasing values. When the second preset counting step and the first preset counting step are both less than 0, it can be considered that they are updated in the order of decreasing values. Exemplarily, the second preset counting step and the first preset counting step can both be 1, and the update order of the sequence counter can be, for example, 1, 2, 3, 4..., and the update order of the activation counter 100 can be, for example, 0, 1, 2, 3, 4... In this embodiment, the probability of row hammering problems occurring in each data row can be accurately assessed, and the risk of the acquisition method being maliciously cracked and targetedly attacked can be effectively reduced, thereby further improving the security of the acquisition method. Moreover, by setting corresponding update orders and counting steps for the sequence counter and the activation counter 100, the efficiency and accuracy of counting can be effectively improved. That is, the embodiment of the present application provides an acquisition method and acquisition circuit with high reliability and high processing efficiency.

[0111] Furthermore, the second preset counting step size and the first preset counting step size may be equal. By adopting the same preset counting step size as described above, the internal logic of the sequence counter and the activation counter 100 may be greatly simplified, thereby improving the technical accuracy of the sequence counter and the activation counter 100. Moreover, since the sequence counter is still a counter whose value changes with the comparison signal, the attack address acquisition method of this embodiment can still avoid the problem of being maliciously cracked, thereby ensuring the reliability of the acquisition method.

[0112] Figure 7 This is a flowchart of a hammer refresh method according to an embodiment. Figure 7 In this embodiment, the hammer refresh method includes steps S100 to S700.

[0113] S100: receiving an activation signal carrying activation row address information, and updating an activation count value corresponding to the activation row address according to a first preset order.

[0114] S200: When the activation count value meets a preset condition, a matching signal is generated.

[0115] S300: In response to the matching signal, latch the active row address.

[0116] S400: Randomly select at least one of the latched active row addresses as the attack address.

[0117] S600: Determine that the adjacent row address of the attack address is a hammer refresh address.

[0118] S700: Perform hammer refresh on the data row corresponding to the hammer refresh address.

[0119] Among them, steps S100 to S400 are the steps of the aforementioned method for obtaining the attack address. In this embodiment, by refreshing the data row corresponding to the hammer refresh address, the influence of the row hammer on the data stored in the adjacent row address can be avoided, thereby improving the reliability of the data stored in the memory. It is understandable that steps S100 to S400 of this embodiment can also be further improved by Figures 3 to 6 The embodiments make an alternative to achieve a more reliable hammer refresh method.

[0120] In one embodiment, determining that the adjacent row address of the attack address is a hammer refresh address includes: respectively obtaining a first adjacent row address and a second adjacent row address of the attack address, wherein the attack address is located between the first adjacent row address and the second adjacent row address. Specifically, Figure 8 This is a schematic diagram of an attack row and adjacent rows according to an embodiment, referring to Figure 8 , there can be multiple attack rows in the storage array, and each attack row can be as follows Figure 8 As shown, they are located in different storage blocks respectively. In other embodiments, one storage block may also include multiple attack rows.

[0121] Furthermore, the attack row can be located in the middle of the memory block, i.e. Figure 8 As shown in the first storage block in , the attack row and its corresponding first adjacent row and second adjacent row are located in the same storage block. The attack row can also be located at the boundary of the storage block, that is, as Figure 8 As shown in the second storage block in FIG, the attack row and its corresponding first adjacent row and second adjacent row are located in different storage blocks. It can be understood that the hammer refresh method of this embodiment can be applied to the attack rows in various positions above, and thus has high reliability.

[0122] Furthermore, determining that the adjacent row address of the attack address is a hammer refresh address includes: respectively obtaining a first adjacent row address and a second adjacent row address of the attack address, wherein the attack address is located between the first adjacent row address and the second adjacent row address. It is understood that in some embodiments, hammer refresh may be performed on only one adjacent row of the attack row, or hammer refresh may be performed on multiple adjacent data rows on a single side of the attack row. The specific determination can be based on the degree to which different adjacent rows are affected by the row hammer effect, for example, based on the distance between the adjacent row and the hammer row, because adjacent adjacent rows are more severely affected by row hammer than more distant adjacent rows, thereby improving the accuracy and efficiency of hammer refresh.

[0123] It should be understood that although Figures 2 to 7 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. In addition, Figures 2 to 7 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.

[0124] Continue to refer Figure 1 An embodiment of the present application provides an attack address acquisition circuit, including an activation counter 100, a count comparison unit 200, an address latch 300 and a random selection unit 400.

[0125] The activation counter 100 is used to receive an activation signal carrying activation row address information and update the activation count value corresponding to the activation row address according to a first preset order. The count comparison unit 200 is connected to the activation counter 100 and is used to generate a hit signal when the activation count value meets a preset condition. The address latch 300 is connected to the count comparison unit 200 and is used to latch the activation row address in response to the hit signal. The random selection unit 400 is connected to the address latch 300 and is used to randomly select at least one of the multiple latched activation row addresses as the attack address. In this embodiment, the activation count value of each row in the storage array is obtained by the activation counter 100, which can accurately assess the probability of row hammering problems occurring in each data row, making it easier for the memory to execute corresponding row hammering avoidance measures according to different occurrence probabilities. Moreover, by randomly selecting one of the multiple alternative activation row addresses as the attack address through the random selection unit 400, the risk of the acquisition method being maliciously cracked and targeted attacks can be effectively reduced, thereby further improving the security of the acquisition method. That is, the embodiment of the present application provides a highly reliable attack address acquisition circuit.

[0126] Figure 9 This is a second structural block diagram of an attack address acquisition circuit according to an embodiment, referring to Figure 9 In this embodiment, the acquisition circuit further includes a sequence counter 500, which is connected to the numerical comparator 210. Sequence counter 500 is configured to respond to the match signal and update the match signal count value according to a second preset order. Specifically, the second preset order may be, for example, Y1, Y2, Y3, Y4... If the match signal count value is Y2 before receiving the match signal, then the match signal count value is updated to Y3 after receiving the match signal. Similar to the first preset order, the second preset order may be an increasing sequence with a fixed change pattern, a decreasing sequence with a fixed change pattern, or a series of sequences with no fixed change pattern. It should be noted that the first preset order may be the same as or different from the second preset order, and this is not specifically limited in this embodiment. In this embodiment, the sequence counter 500 continuously updates the match signal count value based on the match signal, effectively reducing the risk of malicious hacking and targeted attacks on the acquisition circuit, thereby improving the security of the acquisition circuit.

[0127] Furthermore, the count comparison unit 200 includes a numerical comparator 210, which is connected to the activation counter 100 and the sequence counter 500, respectively. The numerical comparator 210 is used to determine that the data row corresponding to the current activation row address is at risk of row hammering when the activation count value is equal to the comparison signal count value, and to generate the comparison signal accordingly. The comparison signal is used to instruct the address latch 300 to latch the activation row address, instruct the sequence counter 500 to update the comparison signal count value, and is also used to instruct the activation counter 100 to reset, thereby realizing a more efficient attack address acquisition circuit.

[0128] Figure 10 This is the third structural block diagram of the attack address acquisition circuit of an embodiment, referring to Figure 10 In this embodiment, the random selection unit 400 includes a random number generator 410 and a multiplexer 420. The random number generator 410 is used to generate a random number that is less than or equal to the number of active row addresses stored in the address latch 300. The multiplexer 420 is connected to the random number generator 410 and the address latch 300, respectively, and is used to select the active row address in the order corresponding to the random number as the attack address.

[0129] Exemplarily, the random number generator 410 may include a plurality of cascaded D flip-flops and a logic gate to generate a multi-bit random number. Cascading means that the output of the previous D flip-flop is connected to the input of the next D flip-flop. In this example, the random number generator 410 includes four D flip-flops and an XOR gate. It is understandable that in other examples, the random number generator 410 may include a greater number of D flip-flops, and the number of D flip-flops corresponds to the number of activation row addresses that the address latch 300 can latch. In addition, this application does not specifically limit the type of logic gates and the number of input terminals. Figure 10 The structure of the random number generator 410 in FIG. 4 is for illustrative purposes only.

[0130] An embodiment of the present application further provides a hammer refresh circuit, which includes the attack address acquisition circuit in the aforementioned embodiment, and also includes an addition and subtraction operator and a refresh module.

[0131] The adder and subtractor is connected to the address latch 300 in the attack address acquisition circuit and is used to perform addition and subtraction operations on the attack address output by the address latch 300 to obtain adjacent row addresses as hammer refresh addresses. For example, if the adder and subtractor respectively perform addition and subtraction operations on the attack address, two hammer refresh addresses can be obtained; if the adder and subtractor respectively perform addition, addition, subtraction, and subtraction operations on the attack address, four hammer refresh addresses can be obtained. It will be understood that the specific operations performed by the adder and subtractor can be determined based on the spacing between adjacent word lines, and the number of hammer refresh addresses obtained by the operations is inversely related to the spacing between adjacent word lines.

[0132] The refresh module is connected to the adder and subtractor and is also connected to the data read / write circuits for the multiple data rows. The refresh module is configured to retrieve the data stored in the data row corresponding to the hammer refresh address via the data read / write circuit, generate refresh data based on the stored data, and rewrite the refresh data to the data row corresponding to the hammer refresh address via the data read / write circuit, thereby implementing a hammer refresh. Optionally, the hammer refresh operation can share at least some of the refresh modules with the automatic refresh operation, thereby reducing the number and size of refresh modules in the memory.

[0133] An embodiment of the present application further provides a memory, including the attack address acquisition circuit as described above. Based on the attack address acquisition circuit described above, this embodiment provides a memory with higher data reliability.

[0134] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0135] The above-described embodiments merely represent several implementation methods of the embodiments of the present application. The descriptions thereof are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that, for those skilled in the art, several variations and improvements can be made without departing from the concept of the embodiments of the present application, and these all fall within the scope of protection of the embodiments of the present application. Therefore, the scope of protection of the patent of the embodiments of the present application shall be based on the appended claims.

Claims

1. A method for obtaining an attack address, characterized in that: include: receiving an activation signal carrying activation row address information, and updating an activation count value corresponding to the activation row address according to a first preset order; When the activation count value meets a preset condition, a hit signal is generated; latching the active row address in response to the match signal; randomly selecting at least one of the latched multiple active row addresses as the attack address, When the activation count value satisfies a preset condition, generating a hit signal comprises: When the activation count value is equal to the comparison signal count value, generating the comparison signal; The acquisition method further includes: in response to the matching signal, updating the matching signal count value according to a second preset order.

2. The acquisition method according to claim 1, characterized in that The randomly selecting at least one of the latched multiple active row addresses as the attack address comprises: In response to a refresh signal, at least one of the latched active row addresses is randomly selected as the attack address.

3. The acquisition method according to claim 1, characterized in that The method further comprises: In response to the match signal, the activation count value corresponding to each of the attack addresses is reset.

4. The acquisition method according to claim 3, characterized in that The updating of the activation count values ​​corresponding to the activation row addresses according to the first preset order includes: updating the activation count values ​​corresponding to the activation row addresses in an ascending order of values; The resetting the activation count value corresponding to each of the attack addresses includes: clearing the activation count value corresponding to each of the attack addresses to zero.

5. The acquisition method according to claim 1, characterized in that The updating of the activation count value corresponding to the activation row address according to the first preset order includes: The activation count value is updated according to a current activation count value corresponding to the activation row address and a first preset counting step.

6. The acquisition method according to claim 5, characterized in that The updating of the comparison signal count value according to a second preset order in response to the comparison signal includes: The matching signal count value is updated according to the current matching signal count value and a second preset counting step.

7. The acquisition method according to claim 6, characterized in that: The first preset counting step length is equal to the second preset counting step length.

8. A hammer refresh method, characterized in that: The method for obtaining an attack address according to any one of claims 1 to 7 further comprises: Determining that an adjacent row address of the attack address is a hammer refresh address; Perform hammer refresh on the data row corresponding to the hammer refresh address.

9. The hammer refresh method according to claim 8, characterized in that: The determining that the adjacent row address of the attack address is a hammer refresh address includes: A first adjacent row address and a second adjacent row address of the attack address are respectively obtained, where the attack address is located between the first adjacent row address and the second adjacent row address.

10. A circuit for acquiring an attack address, characterized in that: include: an activation counter, configured to receive an activation signal carrying activation row address information and update an activation count value corresponding to the activation row address according to a first preset order; a sequence counter, configured to update a count value of the comparison signal in response to the comparison signal according to a second preset order; a count comparison unit connected to the activation counter, and configured to generate a match signal when the activation count value satisfies a preset condition; The counting and comparing unit includes: a numerical comparator connected to the activation counter and the sequence counter, respectively, for generating the matching signal when the activation count value is equal to the matching signal count value; An address latch connected to the counting and comparing unit, and configured to latch the active row address in response to the matching signal; The random selection unit is connected to the address latch and is used to randomly select at least one of the latched multiple active row addresses as the attack address.

11. The acquisition circuit according to claim 10, characterized in that: The random selection unit includes: a random number generator, configured to generate a random number, wherein the random number is less than or equal to the number of activated row addresses stored in the address latch; A multiplexer is connected to the random number generator and the address latch respectively, and is used to select the activation row address in the order corresponding to the random number as the attack address.

12. A memory, characterized in that: The method comprises the attack address acquisition circuit according to any one of claims 10 to 11.

Citation Information

Patent Citations

  • Memory device and memory system for performing a hammer refresh operation and associated operations

    CN108154895A

  • Memory device and refreshing method thereof

    US20190325944A1