Related method of selecting and protecting memory elements of potentially attacked wordlines according to previously updated wordlines

By using random number generators and counters in memory elements to randomly select and protect memory columns that may be attacked, the column hammer effect in DRAM is solved, and the security and efficiency of memory elements are improved.

CN120020955AActive Publication Date: 2025-05-20NAN YA TECH
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202410835803.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-20
Filing Date
2024-02-20
Publication Date
2025-05-20
Estimated Expiration
2044-02-20

AI Technical Summary

Technical Problem

There is a column hammer effect in dynamic random access memory (DRAM). Malicious operators can quickly start the same memory column, causing charge leakage on adjacent unstarted memory columns, changing the contents of the memory columns, and causing component failures.

Method used

A memory element is designed, including a random number generator and a counter, by randomly selecting and protecting memory columns that may be attacked. The random number generator generates a random number based on the last updated character line address and the last accessed character line address. The counter starts counting from the random number. When the counter reaches zero, it obtains the address of the started memory column and protects adjacent memory columns in subsequent update cycles.

Benefits of technology

It effectively prevents the occurrence of column hammer effect, improves the security and effectiveness of memory components, and prevents changes in memory column content caused by malicious operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120020955A_ABST
    Figure CN120020955A_ABST
Patent Text Reader

Abstract

The invention provides a protection method of a memory element. The memory element comprises a plurality of word lines. The protection method includes updating a first word line and a first protected word line of the plurality of word lines during a first update period in response to an update signal, wherein the first protected word line is adjacent to the first access word line; generating, by a random number generator, a first number based on an address of the first word line and an address of the first access word line; in response to the update signal, starting countdown from the first number by means of a counter; when the counter counts zero, obtaining an address of a second access word line which is being accessed by the controller; a second protected wordline is protected during a second update period, wherein the second protected wordline is adjacent to the second access wordline.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of Chinese Patent Application No. 2024101883246, filed on February 20, 2024, with the invention title "Memory Element and Related Method for Selecting and Protecting a Character Line That May Be Attacked Based on a Previously Updated Character Line", and Application No. 2024101883246 claims the priority and benefits of U.S. Provisional Application No. 18 / 514,043, filed on November 20, 2023, the content of which is incorporated herein by reference in its entirety. Technical Field

[0002] The present disclosure relates to a memory element and a method for protecting the same. In particular, it relates to a memory element including a protection circuit for protecting a character line. Background Art

[0003] Dynamic random access memory (DRAM) stores each bit of data in a separate capacitor. A simple DRAM cell includes a single transistor and a single capacitor. If charge is stored in the capacitor, the cell is said to store a logic high (HIGH), depending on the convention used. Then, if no charge is present, the cell is said to store a logic low (LOW). Since the charge in the capacitor dissipates over time, DRAM systems require additional refresh circuits to periodically refresh the charge stored in the capacitor. Since capacitors can only store a very limited amount of charge, to quickly distinguish the difference between logic "1" and logic "0", usually two bit lines (BL) are used for each bit, where the first in the bit line pair is called a bit line true (BLT), and the other is called a bit line complement (BLC). The gate of the single transistor is controlled by a word line (WL).

[0004] Column hammer is a security issue stemming from the unexpected and adverse side effects of DRAM, where memory cells electrically cross each other by leaking charge, potentially changing the content of nearby memory columns (word lines) that were not addressed in the original memory access. Column hammer can be triggered by a specific memory access pattern that rapidly activates the same memory column (word line) multiple times. Thus, the memory cells connected to adjacent word lines leak charge and it is difficult to maintain the original content via subsequent periodic refresh cycles. A malicious operator can exploit the column hammer effect to change the content of nearby memory columns, resulting in component failure. Therefore, a method for protecting the memory (especially its word lines) needs to be developed to mitigate the described problems.

[0005] The above description of "prior art" only provides background art and does not admit that the above description of "prior art" discloses the subject matter of the present disclosure, does not constitute prior art of the present disclosure, and any description of the above "prior art" should not be taken as any part of this case. Summary of the Invention

[0006] An embodiment of the present disclosure provides a memory element. The memory element structure includes a plurality of word lines; and a controller configured to update a first word line and a first protected word line among the plurality of word lines during a first update period in response to an update signal, wherein the first protected word line is adjacent to the first access word line. The memory element further includes a random number generator configured to receive an address of the first word line and an address of the first access word line to generate a first number; and a counter electrically coupled to the random number generator. The counter is configured to receive the first number as an initial value of the counter and is configured to be enabled in response to the update signal. The controller is also configured to obtain an address of a second access word line being accessed when the counter decrements to zero and update a second protected word line during a second update period, wherein the second protected word line is adjacent to the second access word line.

[0007] Another embodiment of the present disclosure provides a memory element. The memory element includes a plurality of word lines; a controller configured to update a first word line and an adjacent word line of a first access word line among the plurality of word lines during a first update period in response to an update signal; a random number generator configured to generate a first number based on the address of the first word line and the address of the first access word line; a counter electrically coupled to the random number generator, wherein the counter is configured to receive the first number as an initial value of the counter and start counting down in response to the update signal; and an address register electrically coupled to the counter, wherein the address register is configured to store an address of a second access word line that is valid when the counter counts down to zero. The controller is also configured to access the address register to obtain the address of the second access word line and protect an adjacent bit line of the second access bit line during a second update period.

[0008] Another embodiment of the present disclosure provides a method for protecting a memory element, wherein the semiconductor element includes a plurality of word lines. The protection method updates a first word line and a first protected word line among the plurality of word lines in a first update period in response to an update signal, wherein the first protected word line is adjacent to the first access word line; generates a first number by a random number generator based on an address of the first word line and an address of the first access word line; starts counting down from the first number by a counter in response to the update signal; when the counter counts to zero, obtains an address of a second access word line being accessed by the controller; protects a second protected word line in a second update period, wherein the second protected word line is adjacent to the second access word line.

[0009] Embodiments of the present disclosure provide a memory element having a protection circuit for selecting and protecting a vulnerable word line. Specifically, the protection circuit of the memory can protect the word line (memory cell) from column hammering. To trigger column hammering, a malicious operator quickly activates the same memory column, causing charge leakage on adjacent unactivated memory columns. This protection circuit provides a random number generator and a counter to randomly select and protect the memory columns that may be attacked. The counter can be configured to count down from a random number generated by the random number generator. When the counter reaches zero, the address of the activated memory column can be obtained. In other words, the memory column is selected from the memory columns activated between multiple update periods. In this case, the selection pool includes the memory columns activated between multiple update periods. The random number generator can generate a random number according to the address of the last updated word line and the address of the last accessed word line (the selected word line that may be attacked) to increase the unpredictability of the random number. Additionally, to prevent the random number generated by the random number generator from exceeding the maximum number of activations between update periods, a digital adjuster modifies the random number to a range from zero to a predetermined number (i.e., the maximum number of activations between update periods). Since the memory columns adjacent to the activated memory column are more likely to be affected by the column hammering effect, they will be protected in subsequent update periods.

[0010] Generally, the number of activations to trigger the column hammer cannot be completed within two update cycles. For example, a memory element with 8192 rows can have approximately 170 activations between multiple update cycles, and the number of activations to trigger the column hammer in the same column can be 10,000 or more. Therefore, protecting additional memory columns that may be subject to the column hammer in each update cycle can eliminate the column hammer problem. In addition, the memory element can include a digital adjuster to determine whether a random number used to select one in the memory column exceeds the maximum number of activations between update cycles (i.e., 170 in this case), and then reduce the random number to between 0 and 170. Therefore, the security and performance of the memory element can be improved.

[0011] The technical features and advantages of the present disclosure have been outlined quite extensively above, so that a better understanding of the following detailed description of the present disclosure can be obtained. Other technical features and advantages constituting the subject matter of the claims of the present disclosure will be described below. Those of ordinary skill in the art to which the present disclosure pertains should understand that the concepts disclosed below and specific embodiments can be quite easily used as a basis for modifying or designing other structures or processes to achieve the same purpose as the present disclosure. Those of ordinary skill in the art to which the present disclosure pertains should also understand that such equivalent constructs cannot depart from the spirit and scope of the present disclosure as defined by the appended claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] A more complete understanding of the present disclosure can be obtained by referring to the detailed description and the claims. The present disclosure should also be understood as being associated with the element numbers of the drawings, and the element numbers of the drawings represent similar elements throughout the description.

[0013] Figure 1 is a schematic diagram illustrating a memory element according to some embodiments of the present disclosure.

[0014] Figure 2 is a schematic diagram illustrating a memory element according to some embodiments of the present disclosure.

[0015] Figure 3 is a schematic diagram illustrating the activation of word lines between update cycles along a timeline according to some embodiments of the present disclosure.

[0016] Figure 3A is a schematic diagram illustrating the word line addresses accessed at each activation between update cycles along a timeline according to some embodiments of the present disclosure.

[0017] Figure 3B is a schematic diagram illustrating the word line addresses accessed at each activation between update cycles along a timeline according to some embodiments of the present disclosure.

[0018] Figure 3Cis a schematic diagram illustrating the character line addresses accessed at each startup between update cycles along a timeline in some embodiments of the present disclosure.

[0019] Figure 4A is a schematic diagram illustrating the character line addresses accessed between update cycles along a timeline in some embodiments of the present disclosure, as well as the updated character line addresses, column hammer target character line addresses, and initial countdown numbers in each update cycle.

[0020] Figure 4B is a schematic diagram illustrating the character line addresses accessed between update cycles along a timeline in some embodiments of the present disclosure, as well as the updated character line addresses, column hammer target character line addresses, and initial countdown numbers in each update cycle.

[0021] Figure 4C is a schematic diagram illustrating the character line addresses accessed between update cycles along a timeline in some embodiments of the present disclosure, as well as the updated character line addresses, column hammer target character line addresses, and initial countdown numbers in each update cycle.

[0022] Figure 4D is a schematic diagram illustrating the character line addresses accessed between update cycles along a timeline in some embodiments of the present disclosure, as well as the updated character line addresses, column hammer target character line addresses, and initial countdown numbers in each update cycle.

[0023] Figure 5 is a flowchart illustrating a method for protecting a memory element in some embodiments of the present disclosure.

[0024] Among them, the reference numerals are explained as follows:

[0025] 1: Memory element

[0026] 2: Memory element

[0027] 3: Schematic diagram

[0028] 3A: Schematic diagram

[0029] 3B: Schematic diagram

[0030] 3C: Schematic diagram

[0031] 4A: Schematic diagram

[0032] 4B: Schematic diagram

[0033] 4C: Schematic diagram

[0034] 4D: Schematic diagram

[0035] 5: Protection method

[0036] 11: Memory cell

[0037] 12: Sense amplifier

[0038] 21: Memory cell

[0039] 22: Controller

[0040] 23: Random number generator

[0041] 23A: First number

[0042] 23B: Second number (modified first number)

[0043] 24: Counter

[0044] 25: Address register

[0045] 26: Digital adjuster

[0046] 111: Memory column

[0047] 112: Memory column

[0048] 113: Memory column

[0049] 114: Memory column

[0050] 131: Column address decoder

[0051] 132: Row address decoder

[0052] 211: Word line

[0053] 212: Word line

[0054] 213: Word line

[0055] 214: Word line

[0056] act_1, act_2, act_3,..., act_N-1, act_N: Activation

[0057] Add CBR : Word line

[0058] Add LRH : Word line

[0059] CBR: Update cycle

[0060] CBR+1: Update cycle

[0061] CBR+2: Update cycle

[0062] CBR+3: Update cycle

[0063] CBR+4: Update cycle

[0064] CBR + 5: Update Cycle

[0065] CDN: Initial Reciprocal Number

[0066] CDN dec : Initial Reciprocal Number

[0067] CDN hex : Initial Reciprocal Number

[0068] N max : Maximum Access Times

[0069] R / W: Read / Write Signal

[0070] RS: Update Signal

[0071] T act : Time Period

[0072] T CBR : Time Period

[0073] WL: Word Line Address

[0074] WL1: Word Line Address

[0075] WL2: Word Line Address

[0076] WL3: Word Line Address Detailed Implementation Manner

[0077] The following describes specific examples of components and configurations to simplify the embodiments of the present disclosure. Of course, these embodiments are only for illustration and are not intended to limit the scope of the present disclosure. For example, when it is described that the first component is formed on the second component, it may include an embodiment where the first and second components are in direct contact, or it may include an embodiment where additional components are formed between the first and second components so that the first and second components are not in direct contact. Additionally, the embodiments of the present disclosure may repeat reference numerals and / or letters in many examples. The purpose of these repetitions is to simplify and clarify, and unless otherwise specified in the text, they do not themselves represent a specific relationship between various embodiments and / or the configurations discussed.

[0078] It should be understood that although the terms first, second, third, etc. may be used herein to describe various elements, components, regions, layers, or sections, these elements, components, regions, layers, or sections are not limited by these terms. On the contrary, these terms are only used to distinguish one element, component, region, layer, or section from another region, layer, or section. Therefore, without departing from the teachings of the inventive concept of progressiveness, the first element, component, region, layer, or section discussed below may be referred to as the second element, component, region, layer, or section.

[0079] The terms used in this specification are for the purpose of describing particular embodiments only and are not intended to limit the present invention. As used herein, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. It will be further understood that when the terms "comprises" and / or "comprising" are used in this specification, these terms specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups of the foregoing.

[0080] It should be understood that in the description of the present disclosure, the term "about" modifies the amounts of the ingredients, compositions, or reactants of the present disclosure, and is intended to mean, for example, the variations in amounts that may occur by typical measurements used to prepare concentrates or solutions and liquid handling procedures. Further, inadvertent errors in the measurement procedures, differences in the manufacture, source, or purity of the ingredients used to make the compositions or practice the methods, etc. may result in variations. In one aspect, the term "about" means within 10% of the reported value. In another aspect, the term "about" means within 5% of the reported value. Further, in yet another aspect, the term "about" means within 10, 9, 8, 7, 6, 5, 4, 3, 2, or 1% of the reported value.

[0081] Figure 1 is a schematic diagram illustrating a memory element 1 of some embodiments of the present disclosure. The memory element 1 may include an array of a plurality of memory cells 11, a plurality of sense amplifiers 12, a column address decoder 131, and a row address decoder 132. In some embodiments, the memory element 1 may be a DRAM.

[0082] Please refer to Figure 1 , the array of memory cells 11 may include a plurality of columns and rows. Each row of memory cells may share a bit line or a pair of bit lines. Each column of memory cells may share a word line. In some embodiments, a single memory cell may include a capacitor and a transistor and is configured to store one bit of data therein. The charge state (charged or discharged) of a capacitor may determine whether the memory cell stores "1" or "0" as a binary value.

[0083] In some embodiments, the memory address applied to an array of memory cells 11 of a matrix can be represented as a column address and a row address, which are processed by a column address decoder 131 and a row address decoder 132. When the column address decoder 131 selects a specific column (e.g., memory column 114) for a read operation (this selection is also referred to as column activation), bits from all the memory cells in the specific column can be transferred to the sense amplifier 12. In some embodiments, one sense amplifier 12 is used for each row of memory cells to temporarily store data. In some embodiments, the row address decoder 132 can select the exact bit from one of the sense amplifiers 12. In some embodiments, the sense amplifier 12 can be configured to receive or transmit data in response to a read / write signal R / W. The write operation decodes the address in a similar manner, but can rewrite an entire column to change the value of a single bit.

[0084] Since data bits are stored in capacitors with a natural discharge rate, the state stored in the memory cells 11 may be lost over time, so it is necessary to rewrite all the memory cells periodically, which is a process called refresh, in order to preserve the information stored on the memory cells. Each memory refresh cycle can refresh one or more columns of memory cells, and all the memory cells can be refreshed repeatedly in consecutive cycles. Memory refresh can be accomplished in multiple types. In some embodiments, memory refresh can be performed by signals of different modes, such as row address strobe (RAS) refresh, column address strobe before row address strobe (CAS-before-RAS) refresh (abbreviated as CBR refresh), and hidden refresh.

[0085] To trigger a column hammer, the same memory column 111 can be activated at a high frequency and in a large amount. When the activation frequency and amount of the memory column 111 are large enough, the charge on the adjacent memory columns 112 and 113 that are not activated may leak, so the data / content stored therein may be lost.

[0086] This protection circuit provides a random number generator and a counter (for a detailed description, please refer to Figure 3 ) to randomly select and protect a possible memory column. The counter can be configured to count down from a random number generated by the random number generator. When the counter reaches zero, the address of the activated memory column (e.g., memory column 111) can be obtained. In other words, the memory column is selected from the memory columns activated between refresh cycles. The adjacent memory columns 112 and 113 near the activated memory column 111 are more likely to suffer from the column hammer effect, so they will be protected in subsequent refresh cycles. In some embodiments, the memory columns 112 and 113 and a planned refresh memory column 114 can be refreshed in subsequent refresh cycles.

[0087] Figure 2 is a schematic diagram illustrating the memory element 2 of some embodiments of the present disclosure. Please refer to Figure 2 , the memory element 2 may include an array of a plurality of memory cells 21, a controller 22, a random number generator 23, a counter 24, an address register 25, and a digital adjuster 26. In some embodiments, the memory element 2 may be a dynamic random access memory (DRAM).

[0088] In some embodiments, the array of memory cells 21 may include multiple word lines. In some embodiments, the array of memory cells 21 may include a possible target word line 211 being accessed, i.e., the column hammer target, two adjacent word lines 212 and 213 adjacent to the possible target word line 211, and normal word lines 214. The normal word lines 214 may be located at any position in the array 21. For example, the normal word line 214 may be an edge word line or a word line sandwiched between two word lines. In one embodiment, the normal word line 214 may be separated from the possible target word line 211. In another embodiment, the normal word line 214 may be adjacent to the possible target word line 211 (not shown in the figure).

[0089] The controller 22 may be configured to update at least one of the multiple word lines by providing an update signal RS during a first update cycle. In some embodiments, the update signal RS may be generated by the controller 22 itself based on a clock signal. In other embodiments, the controller 22 may be configured to update at least one of the multiple word lines in response to an update signal RS during a first update cycle. In such embodiments, the controller 22 may receive the update signal RS from other elements (not shown in the figure). In some embodiments, the update signal RS may be a RAS update instruction or a CBR update instruction. The controller 22 may be configured to update one or more word lines during one update cycle. In some embodiments, the controller 22 may be configured to update one, two, three, four, or more word lines simultaneously. In some embodiments, the controller 22 may be configured to update the array of all memory cells 21 cycle by cycle. In some embodiments, the controller 22 may be configured to update the array of all memory cells 21 in a predetermined pattern (i.e., the update pattern).

[0090] The random number generator 23 can be configured to generate a first number 23A. The first number 23A can be a positive integer. In some embodiments, the first number 23A can be binary. The first number 23A can be represented by a binary sequence having more than 2 bits. For example, the first number 23A can be represented by an 8-bit binary sequence. That is, the first number 23A can be a number in the range of 0 to 255. In other embodiments, the first number 23A can be more or less than 8 bits.

[0091] Please refer to Figure 2 , the random number generator 23 can include a logic gate. The logic gate 23 can include an OR gate, an AND gate, an XOR gate, an XNOR gate, etc. In some embodiments, the random number generator 23 can be an XOR gate.

[0092] In some embodiments, the logic gate 23 can have a first input terminal, a second input terminal, and an output terminal. In some embodiments, the logic gate 23 can be configured to receive, at the first input terminal, an address of a word line Add updated in a previous update cycle CBR . The logic gate 23 can be configured to receive, at the second input terminal, an address of the accessed word line Add LRH , i.e., a possible target column hammer word line located in a previous update cycle. In some embodiments, the logic gate 23 can be configured to generate the first number 23A in response to the address of the word line Add CBR and the address of the accessed word line Add LRH .

[0093] In some embodiments, both the address of the word line Add CBR and the address of the accessed word line Add LRH can be represented by a 4-bit hexadecimal sequence. The address of the word line represented by a 4-bit hexadecimal sequence can be converted into a 16-bit binary sequence.

[0094] In some embodiments, the logic gate 23 can be configured to generate the first number 23A based on a part of the address of the word line Add CBR and a part of the address of the accessed word line Add LRH . In some embodiments, when the address of the word line Add CBR is represented by a 4-bit hexadecimal sequence, this part of the address of the word line Add CBR can be 2 bits, i.e., half of the total bit length. In other embodiments, regardless of the total bit length, this part of the address of the word line Add CBR can be the last 2 bits. In some embodiments, the hexadecimal word line Add CBRThe address is converted to binary. In some embodiments, the 2-bit hexadecimal of the address of word line Add CBR can be converted to 8-bit binary.

[0095] In some embodiments, when accessing the address of word line Add LRH represented as a 4-bit hexadecimal sequence, this part of the address of word line Add LRH can be 2 bits, which is half of the total bit length. In other embodiments, this part of the address of word line Add LRH can be the last 2 bits, regardless of the total bit length. In some embodiments, the hexadecimal address of word line Add LRH can be converted to binary. In some embodiments, the 2-bit hexadecimal of the address of bit line Add LRH can be converted to 8-bit binary.

[0096] The word line Add for the random number generator 23 CBR and the fetched part of the accessed word line Add LRH can have the same bit length. In some embodiments, the fetched bits of the random number generator 23 for word line Add CBR and the accessed word line Add LRH can be determined according to the size of the memory array.

[0097] In some embodiments, the output of the random number generator 23 can be coupled to the counter 24. The random number generator 23 can output a first number 23A at the output to the counter 24.

[0098] The random number generator 23 can be configured to generate a random number (i.e., the first number 23A) in response to the address of word line Add CBR and the address of the accessed word line Add LRH . Although the word line Add CBR can be predetermined according to the update pattern, the accessed word line Add LRH can be randomly selected from the memory array. Therefore, the first number 23A may be more difficult to predict. Thus, the security of the memory element 2 can be improved.

[0099] The digital adjuster 26 can be connected to the random number generator 23 and is configured to receive a first number 23A. The digital adjuster 26 can be a circuit that reduces the first number 23A to less than a critical value. In some embodiments, the digital adjuster 26 can be configured to generate a modified first number 23B (or a second number 23B) based on the first number 23A. In some embodiments, when the first number 23A is greater than a first predetermined number, the digital adjuster 26 can modify the first number 23A to the modified first number 23B. In some embodiments, the first predetermined number is the maximum number of accesses between update cycles (for a detailed description, see Figure 3 ). After modification, the modified first number 23B is less than the first predetermined number. The modified first number 23B can be less than the first number 23A.

[0100] Figure 3 is schematic Figure 3 , illustrating the activation of word lines between update cycles along a timeline in some embodiments of the present disclosure.

[0101] Please refer to Figure 3 , along the timeline (i.e., the x-axis), a time period T CBR is located between a first update cycle CBR and a second update cycle CBR+1. In some embodiments, the second update cycle CBR+1 immediately follows the first update cycle CBR. In some embodiments, each of the first update cycle CBR and the second update cycle CBR+1 can include a period for an update operation and an idle period. The idle period mentioned here refers to the waiting time from the start of the update cycle CBR to the start of the update cycle CBR+1. Therefore, the time period T CBR can be from the start point of the first update cycle CBR to the start point of the second update cycle CBR+1.

[0102] In some embodiments, N activations (act_1, act_2, act_3,..., act_N-1, act_N) occur between the first update cycle CBR and the second update cycle CBR+1. Each activation act_1, act_2, act_3, act_N-1, and act_N represents an access to a word line. The time period T act is between two activations. For example, the time period T act can be between activation act_1 and act_2. In some embodiments, the time period T act can be the minimum necessary time to access a word line (such as the first activation act_1).

[0103] To clearly illustrate the present disclosure, a memory array with 8k character lines is taken as an example. The memory array may include 8192 character lines. The addresses of the character lines may be represented by a hexadecimal sequence, for example, using 4 bits. In some embodiments, the time to update all the character lines (i.e., 8192 character lines) may be 64 ms. At this time, the time period T required to update one character line CBR can be calculated as 64 ms / 8192, so the time period T CBR is 7.8125 μs. In other words, for a total of 8k character lines, the time period T CBR from the start of the first update cycle to the start of the second update cycle can be 7.8125 μs. Assume the time period T act is 45.75 ns, then the maximum number of accesses N max between update cycles can be calculated according to the formula . Therefore, the maximum number of accesses N max can be 7.8125 μs / 45.75 ns = 170.765 ≈ 170, that is Figure 3 the number N in is 170. In this embodiment, 170 character lines can be accessed between update cycles. Accordingly, the first number 23A received by the counter 24 can be modified to be lower than a predetermined number (for example, 170 in this embodiment).

[0104] In some embodiments, the first number 23A may be less than a predetermined number, which is related to the time period T act used to access the character lines and the time period T CBR between the first update cycle CBR and the second update cycle CBR + 1. In some embodiments, the counter 24 may be configured to reset the initial value when the first number 23A is greater than the predetermined number. For example, the initial value of the counter 24 may be reset to zero or a constant less than the predetermined number. Therefore, the counter 24 can start counting down from an initial value within the range from 0 to the predetermined number (i.e., the maximum number of accesses between update cycles), and when it decrements to zero, the character line can be selected to be protected during the subsequent update cycle.

[0105] Please refer again to Figure 2, the modified first number 23B can be represented in the same form as the first number 23A. In some embodiments, both the first number and the modified number can be binary. For example, if the first number 23A is represented by an 8-bit binary sequence, then the modified first number 23B is also represented by an 8-bit binary sequence. In some embodiments, the first number 23A can be represented by a binary sequence having Bit7, Bit6, Bit5, Bit4, Bit3, Bit2, Bit1, and Bit0. The modified first number 23B can be represented by a binary sequence having Bit7', Bit6', Bit5', Bit4', Bit3', Bit2', Bit1', and Bit0'.

[0106] The difference between the first number 23A and the modified first number 23B can be one bit of the binary sequence. For example, a most significant bit (msb) of the first number 23A can be different from the most significant bit of the modified first number 23B. That is, Bit7' of the modified first number 23B is different from Bit7 of the first number 23A. In some embodiments, Bit6' to Bit0' of the modified first number 23B can be the same as Bit6 to Bit0 of the first number 23A. In another embodiment, the modified first number 23B can be reset to zero by the digital adjuster 26. Accordingly, Bit7' to Bit0' of the modified first number 23B are logic "0".

[0107] Conversely, when the first number 23A is less than the first predetermined number, the digital adjuster 26 does not take any action on the first number 23A. In this case, the modified first number 23B will be the same as the original first number 23A.

[0108] The counter 24 can be electrically coupled to the random number generator 23 and the digital adjuster 26. In some embodiments, the counter 24 can be electrically coupled to the random number generator 23 via the digital adjuster 26. The counter 24 can be configured to receive the modified first number 23B as an initial value of the counter 24. In one embodiment, when the first number 23A is less than the first predetermined number, the modified first number 23B is the same as the first number 23A, and the counter 24 decrements from the modified first number 23B (i.e., the first number 23A). In another embodiment, when the first number 23A is greater than the first predetermined number, the first number 23A is modified to the modified first number 23B that is less than the first predetermined number, and the counter 24 decrements from the modified first number 23B that is different from the first number 23A.

[0109] In some embodiments, the counter 24 is configured to start counting in response to an update signal RS received from the controller 22. In other words, the counter 24 can be configured to start counting down in response to the update signal RS. The counter 24 can be configured to decrement from an initial value (i.e., the first number 23A or the modified first number 23B).

[0110] In some embodiments, the counter 24 can be configured to decrement in response to an access signal indicating an access to one of the word lines.

[0111] The address register 25 can be electrically coupled to the counter 24. The address register 25 can be configured to obtain the address of the first word line 211 (or the possible target bit line 211) that is valid when the counter 24 decrements to zero, and store the address.

[0112] Figure 3A is schematic Figure 3A , illustrating the word line addresses accessed at each activation between update cycles CBR and CBR+1 along the timeline in some embodiments of the present disclosure.

[0113] Please refer to Figure 3A , the word line address WL1 is accessed at each start of act_1, act_2, act_3, act_4,... and act_N. In this case, regardless of the initial value of the counter 24, the address register 25 stores the most frequently accessed word line address WL1. In other words, the word line address WL1 is most likely to be the target of a malicious operator. Therefore, selecting a word line adjacent to the word line address WL1 to be protected can prevent column hammering.

[0114] Figure 3B is schematic Figure 3B , illustrating the word line addresses accessed at each start between update cycles CBR and CBR+1 along the timeline in some embodiments of the present disclosure.

[0115] Please refer to Figure 3B, the character line address WL1 is accessed at the start of act_1. The character line address WL2 is accessed at the start of act_2. The character line address WL1 is accessed at the start of act_3. The character line address WL2 is accessed at the start of act_4. The character line address WL2 is accessed at the start of act_N. That is, only the character line addresses WL1 and WL2 are accessed. In this case, regardless of the initial value of the counter 24, the address register 25 stores the character line address WL1 or WL2 with the most access times. In some embodiments, the probability of the character line addresses WL1 and WL2 being attacked is 50% each. In other words, the character line addresses WL1 and WL2 are most likely to be targeted by an attacker. Therefore, selecting a character line adjacent to the character line address WL1 or WL2 for protection can prevent column hammering.

[0116] Figure 3C is schematic Figure 3C , illustrating the character line addresses accessed at each start between the update cycles CBR and CBR + 1 along the timeline for some embodiments of the present disclosure.

[0117] Please refer to Figure 3C , the character line address WL1 is accessed at the start of act_1. The character line address WL2 is accessed at the start of act_2. The character line address WL3 is accessed at the start of act_3. The character line address WL1 is accessed at the start of act_4. The character line address WL2 is accessed at the start of act_N - 1. The character line address WL3 is accessed at the start of act_N. In some embodiments, the character line addresses WL1, WL2, and WL3 are accessed repeatedly in sequence. That is, only the character line addresses WL1, WL2, and WL3 are accessed between update cycles. In this case, the address register 25 stores one of the character line addresses WL1, WL2, and WL3. In some embodiments, the probability of the character line addresses WL1, WL2, and WL3 being attacked can be approximately 33.33%. In other words, the character line addresses WL1, WL2, and WL3 are most likely to be targeted by a malicious operator. Therefore, selecting a character line adjacent to the character line address WL1, WL2, or WL3 for protection can prevent column hammering.

[0118] Please refer to Figures 3A - 3C , the address of the character line to be protected can be randomly selected from those character lines that are valid during two update cycles. The character line is selected from the character lines started between update cycles. In this case, the selection pool includes the character lines started between update cycles.

[0119] Please refer back to Figure 2, the controller 22 can be configured to access the address register 25 during a second update period to obtain the address of the first word line and protect the second word lines 212 / 213 (i.e., the adjacent word lines 212 or 213). To protect the second word lines 212 / 213, the controller can be configured to update the second word lines 212 / 213 in response to an update signal during the second update period. In some embodiments, the second update period is after the first update period. For example, the second update period is a subsequent update period of the first update period. In some embodiments, the second word lines 212 / 213 are adjacent to the first word line 211.

[0120] The controller 22 can be configured to update one or more word lines during an update period. In some embodiments, the controller 22 can be configured to update one, two, three, four, or more word lines simultaneously. The controller 22 can be configured to update the adjacent word lines 212 and 213 during the same update period. In some embodiments, in addition to the second word lines 212 / 213, the controller 22 can also be configured to update the third word line 214 in response to an update signal RS during the second update period, wherein the address of the third word line 214 is the same as the address of the first word line 211.

[0121] In some embodiments, the controller 22 can be configured to update one word line adjacent to the possible target word line 211 and another word line separated from the possible target word line 211. For example, the word line 212 and the word line 214 can be updated during the second update period. In some embodiments, in one update period, the controller 22 can be configured to update one normal word line (e.g., the word line 214) and one high-risk word line (e.g., the word line 212 or 213) according to a predetermined update pattern determined by the random number generator 23 and the counter 24. That is, in one update period, at least one normally updated word line and at least one word line having a high risk of column hammer effect can be updated simultaneously.

[0122] In the present disclosure, when the counter 24 decrements to zero, the address of the activated first word line 211 (or the possible target word line 211) can be obtained. In this case, the address of the word line to be protected can be randomly selected from those word lines that are valid during two update periods. Additionally, the digital adjuster 26 modifies the first number 23A to be within the range of 0 to a first predetermined number to prevent the first number 23A from exceeding the maximum activation number between update periods.

[0123] Figure 4A is schematic Figure 4A , illustrating the word line addresses accessed between the update periods CBR and CBR + 1 along the timeline in some embodiments of the present disclosure, and the updated word line addresses Add in each update periodCBR , Column Hammer Target Character Line Address Add LRH and the initial countdown number CDN.

[0124] Please refer to Figure 4A , at the start of act_1, the accessed character line address WL is 1235. At the start of act_2, the accessed character line address WL is 0021. At the start of act_3, the accessed character line address WL is 1235. At the start of act_59, the accessed character line address WL is 1235. At the start of act_60, the accessed character line address WL is 0021. At the start of act_N - 1, the accessed character line address WL is 1235. At the start of act_N, the accessed character line address WL is 0021. That is, only two character line addresses 1235 and 0021 are accessed. In some embodiments, Figure 4A the character line addresses in

[0125] In the update cycle CBR, the updated character line address AddCBR can be, for example, 1ABC. When the update cycle CBR is the initial update cycle, there is no previous update cycle, so the possible target column hammer character lines are at the address Add LRH (in the previous update cycle) can be 0000. The character line address WL of hexadecimal 1ABC is equivalent to decimal 6844 and equivalent to binary 0001101010111100. As Figure 2 discussed, the random number generator 23 can be configured to respond to the last 2 bits of the hexadecimal updated character line address Add CBR and the column hammer target character line address Add LRH to generate the first number 23A.

[0126] In response to the last 2 bits of the updated character line address Add CBR being BC and the last 2 bits of the column hammer target character line address Add LRH being 00, the initial countdown number CDN hex , that is, the first number 23A (the initial number of the counter 24), according to the operation of the logic gate 23 (such as XOR), can be hexadecimal 3C. In some embodiments, the initial countdown number CDN hex = 3C can be equal to the initial countdown number CDN dec= 60. In this case, the counter 24 can count down from 60, and the address register 25 can be configured to obtain the word line address accessed at the start act_60 between the update cycles CBR and CBR + 1, which is the word line address (WL) of 0021. Thus, in the next update cycle CBR + 1, the column hammer target word line address Add LRH will be 0021. That is, in the update cycle CBR + 1, the adjacent word line address 0021 (e.g., the word line address that is 0020 or 0022) can be protected.

[0127] In the update cycle CBR + 1, the updated word line address Add CBR can be 1ABD, and the column hammer target word line address Add LRH can be 0021. The word line address WL of hexadecimal 1ABD can be equivalent to decimal 6845 and equivalent to 0001101010111101.

[0128] In response to the last 2 bits of the updated word line address Add CBR being BD and the last 2 bits of the column hammer target word line address Add LRH being 21, according to the operation (e.g., XOR) of the logic gate 23 in the update cycle CBR + 1, the initial countdown number CDN hex can be hexadecimal 9C. In some embodiments, the initial countdown number CDN hex = 9C can be equal to the initial countdown number CDN dec = 156. In this case, the counter 24 can count down from 156, and the address register 25 can be configured to obtain the word line address accessed at the start act_156 between the update cycles CBR + 1 and CBR + 2 (see Figure 4B ).

[0129] Figure 4B is schematic Figure 4B , illustrating the word line addresses accessed between the update cycles CBR + 1 and CBR + 2 along the timeline in some embodiments of the present disclosure, as well as the updated word line address Add CBR , the column hammer target word line address Add LRH and the initial countdown number CDN in each update cycle.

[0130] Please refer to Figure 4B, at the start of act_1, the accessed word line address WL is 1235. At the start of act_2, the accessed word line address WL is 0021. At the start of act_3, the accessed word line address WL is 1235. At the start of act_155, the accessed word line address WL is 1235. At the start of act_156, the accessed word line address WL is 0021. At the start of act_N - 1, the accessed word line address WL is 1235. At the start of act_N, the accessed word line address WL is 0021. That is, only two word line addresses, 1235 and 0021, are accessed.

[0131] In the update period CBR + 1, update the word line address Add CBR Can be 1ABD, the column hammer target word line address Add LRH Can be 0021. As Figure 4A As shown, in response to the update word line address Add CBR The last 2 bits of which are BD and the column hammer target word line address Add LRH The last 2 bits of which are 21, the initial countdown number CDN hex In the update period CBR + 1 can be hexadecimal 9C. In some embodiments, the initial countdown number CDN hex = 9C can be equal to the initial countdown number CDN dec = 156. In this case, the counter 24 can count down from 156, and the address register 25 can be configured to obtain the word line address accessed at the start of act_156 between the update periods CBR + 1 and CBR + 2, which is the word line address (WL) of 0021. Accordingly, in the subsequent update period CBR + 2, the column hammer target word line address Add LRH Will also be 0021. That is, in the update period CBR + 2, the adjacent word line addresses of 0021 (such as the word line addresses of 0020 or 0022) can be protected.

[0132] In the update period CBR + 2, update the word line address Add CBR Can be 1ABE, the column hammer target word line address Add LRH Can be 0021. The word line address WL of hexadecimal 1ABE can be equivalent to decimal 6846 and equivalent to 0001101010111110.

[0133] In response to the update word line address Add CBR The last 2 bits of which are BE and the column hammer target word line address Add LRH The last 2 bits of which are 21, then in the update period CBR + 2, the initial countdown number CDN hexCan be 9F in hexadecimal. In some embodiments, the initial countdown number CDN hex = 9F can be equal to the initial countdown number CDN dec = 159. In this case, the counter 24 can count down from 159, and the address register 25 can be configured to obtain the word line address accessed at the start act_159 between the update cycles CBR + 2 and CBR + 3 (see Figure 4C ).

[0134] Figure 4C is schematic Figure 4C , illustrating the word line addresses accessed between the update cycles CBR + 2 and CBR + 3 along the timeline in some embodiments of the present disclosure, as well as the updated word line address Add CBR in each update cycle, the column hammer target word line address Add LRH and the initial countdown number CDN.

[0135] Please refer to Figure 4C , the word line address WL accessed at the start act_1 is 1235. The word line address WL accessed at the start act_2 is 0021. The word line address WL accessed at the start act_3 is 1235. The word line address WL accessed at the start act_159 is 1235. The word line address WL accessed at the start act_160 is 0021. The word line address WL accessed at the start act_N - 1 is 1235. The word line address WL accessed at the start act_N is 0021. That is, only two word line addresses 1235 and 0021 are accessed.

[0136] In the update cycle CBR + 2, the updated word line address Add CBR can be 1ABE, and the column hammer target word line address Add LRH can be 0021. As Figure 4B shown, in response to the last 2 bits of the updated word line address Add CBR being BE and the last 2 bits of the column hammer target word line address Add LRH being 21, the initial countdown number CDN hex in the update cycle CBR + 2 can be 9F in hexadecimal. In some embodiments, the initial countdown number CDN hex = 9F can be equal to the initial countdown number CDN dec= 159. In this case, the counter 24 can count down from 159, and the address register 25 can be configured to obtain the word line address accessed at the start act_159 between update cycles CBR+2 and CBR+3, which is the word line address (WL) of 1235. Accordingly, in the subsequent update cycle CBR+3, the column hammer target word line address Add LRH will also be 1235. That is, in the update cycle CBR+3, the adjacent word line addresses that are 1235 (such as the word line addresses that are 1234 or 1236) can be protected.

[0137] In the update cycle CBR+3, the updated word line address Add CBR can be 1ABF, and the column hammer target word line address Add LRH can be 1235. The word line address WL of hexadecimal 1ABF can be equivalent to decimal 6847 and equivalent to 0001101010111111.

[0138] In response to the last 2 bits of the updated word line address Add CBR being BF and the last 2 bits of the column hammer target word line address Add LRH being 35, the initial countdown number CDN hex in the update cycle CBR+3 can be hexadecimal 8A. In some embodiments, the initial countdown number CDN hex = 8A can be equal to the initial countdown number CDN dec = 138. In this case, the counter 24 can count down from 138, and the address register 25 can be configured to obtain the word line address accessed at the start act_138 between update cycles CBR+3 and CBR+4 (see Figure 4D ).

[0139] Figure 4D is schematic Figure 4D , illustrating the word line addresses accessed between update cycles CBR+3 and CBR+4 along the timeline in some embodiments of the present disclosure, as well as the updated word line address Add CBR , the column hammer target word line address Add LRH and the initial countdown number CDN in each update cycle.

[0140] Please refer to Figure 4D, at the start of act_1, the accessed word line address WL is 1235. At the start of act_2, the accessed word line address WL is 0021. At the start of act_3, the accessed word line address WL is 1235. At the start of act_137, the accessed word line address WL is 1235. At the start of act_138, the accessed word line address WL is 0021. At the start of act_N - 1, the accessed word line address WL is 1235. At the start of act_N, the accessed word line address WL is 0021. That is, only the word line addresses 1235 and 0021 are accessed.

[0141] In the update cycle CBR + 3, the updated word line address AddCBR can be 1ABF, and the column hammer target word line address Add LRH can be 1235. As Figure 4C shown, in response to the updated word line address Add CBR with the last 2 bits being BF and the column hammer target word line address Add LRH with the last 2 bits being 35, the initial countdown number CDN hex in the update cycle CBR + 3 can be hexadecimal 8A. In some embodiments, the initial countdown number CDN hex = 8A can be equal to the initial countdown number CDN dec = 138. In this case, the counter 24 can start counting down from 138, and the address register 25 can be configured to obtain the word line address accessed at the start of act_138 between the update cycles CBR + 3 and CBR + 4, which is the word line address (WL) of 0021. Accordingly, in the subsequent update cycle CBR + 4, the column hammer target word line address Add LRH will also be 0021. That is, in the update cycle CBR + 4, the adjacent word line addresses of 0021 (such as the word line addresses of 0020 or 0022) can be protected.

[0142] In the update cycle CBR + 4, the updated word line address Add CBR can be 1AC0, and the column hammer target word line address Add LRH can be 0021. The word line address WL of hexadecimal 1AC0 is equivalent to decimal 6848 and is equivalent to 0001101011000000.

[0143] For the update cycle CBR + 4, in response to the last 2 bits of the updated word line address Add CBR being C0, the column hammer target word line address Add LRHIf the last two digits are 21, then the first number 23A can be E1 in hexadecimal, which is equivalent to 225 in decimal and 11100001 in binary. In this case, the first number 23A is greater than the first predetermined number (170), so the first number 23A will be modified by the digital adjuster 26 to the modified first number 23B. For example, the digital adjuster 26 can be configured to reset the most significant bit (msb) of the first number 23A in binary. Thus, the modified first number 23B can be 01100001, which is equivalent to 197 in decimal and 61 in hexadecimal.

[0144] Therefore, in the update period CBR + 4, the initial countdown number CDN hex can be 61 in hexadecimal (CDN dec = 97). In this case, the counter 24 can start counting down from 97, and the address register 25 can be configured to obtain the word line address (not shown in the figure) accessed at the start act_97 between the update periods CBR + 4 and CBR + 5.

[0145] Please refer to Figures 4A - 4D . The address of the word line to be protected can be randomly selected from those word lines that are valid during two update periods. The word line is selected from the word lines activated between the update periods. In this case, the selection pool includes the word lines activated between the update periods (i.e., the word line addresses that are 0021 and 1235).

[0146] Figure 5 is a flow diagram illustrating a method 5 for protecting memory elements according to some embodiments of the present disclosure. In some embodiments, the protection method 5 is used to protect the word lines included in the memory element. In some embodiments, the memory element may include multiple word lines.

[0147] In step 51, a first word line and a first protected word line among multiple word lines can be updated during a first update period in response to an update signal, where the first protected word line is adjacent to the first access word line. In some embodiments, the controller of the memory element (e.g., Figure 2 the controller 22 in Figure 4C can update one or more word lines in each update period in response to the update signal. In some embodiments, in the first update period (e.g., LRH the update period CBR + 2 in Figure 2 ), the controller can be configured to update a normal word line (e.g., the word line address that is 1ABE) and a high-risk bit line (e.g., the word line addresses that are 0020 or 0022, adjacent to Add LRH = 0021) according to a predetermined update pattern. In some embodiments, step 51 can be performed by Figure 2 the controller 22.

[0148] In step 52, a random number generator can generate a first number based on an address of the first character line and an address of the first access character line. In some embodiments, the random number generator (e.g., Figure 2 the random number generator 23 in Figure 2 ) can be configured to generate a random number based on a portion of the address of the first character line and a portion of the address of the first access character line. In some embodiments, step 52 can be performed by

[0149] the random number generator 23 in Figure 2 .

[0150] In step 53, a counter can count down from the first number in response to the update signal. In some embodiments, in response to the update signal, the counter can be configured to start counting. In some embodiments, each count down is triggered by an access signal indicating an access to a character line. In some embodiments, step 53 can be performed by Figure 2 the counter 24 shown in

[0150] . Figure 4C In step 54, when the counter counts to zero, a controller can obtain an address of a second access character line being accessed. In some embodiments, when the counter counts down to zero, the address of the second access character line can be obtained (e.g., as shown in Figure 4C , the character line address where the access is 1235 in act_159 start-up) and stored in an address register (e.g., as shown in Figure 2 the address register 25). The controller (e.g., Figure 2 the controller 22 in Figure 2 ) can be configured to access the address register and obtain the address of the second access character line. In some embodiments, step 54 can be performed by the controller 22 with or without Figure 2 the address register 25 shown in Figure 2 .

[0151] In step 55, a second protected character line can be protected during a second update period, where the second protected character line is adjacent to the second access character line. In some embodiments, the second protected character line can be updated during the second update period (e.g., the character line addresses 1234 or 1236 can be updated during the update period CBR + 3, as shown in Figure 4C ). In some embodiments, step 55 can be performed by Figure 2 the controller 22 of Figure 2 .

[0152] To implement column hammering, a malicious operator often accesses one or more target word lines at a high frequency. The large number of accesses to the target word lines can cause the column hammering effect to occur on the word lines adjacent to the target word lines. That is, under the column hammering effect, even if the nearby word lines are not accessed, the content of the nearby word lines may change due to the leaked charge.

[0153] The present disclosure provides a memory element that can identify target word lines that may be attacked and protect the word lines adjacent to the possible target word lines. A random number generator can generate a random number as the initial value of a counter, and the address of the accessed target word line can be obtained when the counter counts down to zero. Additionally, to prevent the random number generated by the random number generator from exceeding the maximum starting number between update cycles, a digital adjuster modifies the random number to a range from zero to a predetermined number (i.e., the maximum starting number between update cycles). Thus, the word lines adjacent to the frequently accessed target word lines can be updated to maintain the content.

[0154] An embodiment of the present disclosure provides a memory element. The memory element structure includes multiple word lines; and a controller configured to update a first word line and a first protected word line among the multiple word lines during a first update cycle in response to an update signal, where the first protected word line is adjacent to the first accessed word line. The memory element further includes a random number generator configured to receive an address of the first word line and an address of the first accessed word line to generate a first number; and a counter electrically coupled to the random number generator. The counter is configured to receive the first number as an initial value of the counter and is configured to be turned on in response to the update signal. The controller is also configured to obtain an address of a second accessed word line being accessed when the counter counts down to zero and update a second protected word line during a second update cycle, where the second protected word line is adjacent to the second accessed word line.

[0155] Another embodiment of the present disclosure provides a memory element. The memory element includes a plurality of word lines; a controller configured to update a first word line and an adjacent word line of a first access word line among the plurality of word lines during a first update period in response to an update signal; a random number generator configured to generate a first number based on the address of the first word line and the address of the first access word line; a counter electrically coupled to the random number generator, wherein the counter is configured to receive the first number as an initial value of the counter and start counting down in response to the update signal; and an address register electrically coupled to the counter, wherein the address register is configured to store an address of a second access word line that is valid when the counter counts down to zero. The controller is also configured to access the address register to obtain the address of the second access word line and protect adjacent bit lines of the second access bit line during a second update period.

[0156] Another embodiment of the present disclosure provides a method for protecting a memory element, wherein the semiconductor element includes a plurality of word lines. The protection method updates a first word line and a first protected word line among the plurality of word lines during a first update period in response to an update signal, wherein the first protected word line is adjacent to the first access word line; generates a first number by a random number generator based on an address of the first word line and an address of the first access word line; starts counting down from the first number by a counter in response to the update signal; obtains an address of a second access word line being accessed by the controller when the counter counts to zero; protects a second protected word line during a second update period, wherein the second protected word line is adjacent to the second access word line.

[0157] Embodiments of the present disclosure provide a memory element having a protection circuit for selecting and protecting a vulnerable word line. Specifically, the protection circuit of the memory can protect the word line (memory cell) from column hammering. To trigger column hammering, a malicious operator rapidly activates the same memory column, causing charge leakage on adjacent unactivated memory columns. The protection circuit provides a random number generator and a counter to randomly select and protect the memory columns that may be attacked. The counter can be configured to count down from a random number generated by the random number generator. When the counter reaches zero, an address of the activated memory column can be obtained. In other words, the memory column is selected from the memory columns activated between multiple update cycles. In this case, the selection pool includes the memory columns activated between multiple update cycles. The random number generator can generate a random number based on the address of the last updated word line and the address of the last accessed word line (the selected word line that may be attacked), so as to increase the unpredictability of the random number. Additionally, to prevent the random number generated by the random number generator from exceeding the maximum number of activations between update cycles, a digital adjuster modifies the random number to a range from zero to a predetermined number (i.e., the maximum number of activations between update cycles). Since the memory columns adjacent to the activated memory column are more likely to be affected by the column hammer effect, they will be protected in subsequent update cycles.

[0158] Generally, the number of activations to trigger column hammering cannot be completed within two update cycles. For example, a memory element with 8192 rows can have approximately 170 activations between multiple update cycles, and the number of activations to trigger column hammering in the same column can be 10000 or more. Therefore, protecting additional memory columns that may be subject to column hammering in each update cycle can eliminate the column hammer problem. Additionally, the memory element can include a digital adjuster to determine whether the random number used to select one in the memory column exceeds the maximum number of activations between update cycles (i.e., 170 in this case), and then reduce the random number to a range from 0 to 170. Thus, the security and performance of the memory element can be improved.

[0159] Although the present disclosure and its advantages have been described in detail, it should be understood that various changes, substitutions, and alternatives can be made without departing from the spirit and scope of the present disclosure as defined by the claims. For example, many of the above processes can be implemented in different ways, and many of the above processes can be replaced by other processes or combinations thereof.

[0160] Moreover, the scope of the present application is not limited to the specific embodiments of the processes, machines, manufactures, compositions of matter, means, methods, and steps described in the specification. Those skilled in the art can understand from the disclosure of the present disclosure that existing or future-developed processes, machines, manufactures, compositions of matter, means, methods, or steps that can be used in accordance with the present disclosure and have the same functions or achieve substantially the same results as the corresponding embodiments described herein. Accordingly, such processes, machines, manufactures, compositions of matter, means, methods, or steps are included in the claims of the present application.

Claims

1. A method for protecting a memory element, wherein the memory element comprises a plurality of word lines, comprising: updating a first word line and a first protected word line of the plurality of word lines during a first update cycle in response to an update signal, wherein the first protected word line is adjacent to a first access word line; generating a first number by a random number generator based on an address of the first word line and an address of the first access word line; In response to the update signal, a counter starts counting down from the first number; When the counter counts to zero, an address of a second access word line being accessed is obtained by a controller; A second protected word line is protected during a second refresh cycle, wherein the second protected word line is adjacent to the second access word line. 2 . The protection method as claimed in claim 1 , wherein the first number is represented by a binary sequence of more than 2 bits.

3. The protection method as claimed in claim 2, wherein the first number is an 8-bit binary sequence.

4. The protection method of claim 1, wherein the first number is less than a first predetermined number, wherein the first predetermined number is associated with a first time period and a second time period, the first time period is used to access a word line, and the second time period is between the first update cycle and the second update cycle. 5 . The protection method as claimed in claim 4 , wherein the memory element further comprises a digital adjuster configured to reset a most significant bit of the first number when the first number is greater than the first predetermined number. The protection method as claimed in claim 1 , wherein the random number generator comprises an XOR gate.

7. The protection method of claim 1, wherein the address of the first word line and the address of the first access word line are both represented by a hexadecimal sequence having 4 bits.

8. The protection method of claim 7, wherein the random number generator is configured to generate the first number based on a first portion of the address of the first word line and a first portion of the address of the first access word line.

9. The protection method of claim 1, wherein the memory device further comprises an address register electrically connected to the counter, wherein the address register is configured to obtain and store the address of the first access word line accessed when the counter is decremented to zero.

10. The protection method of claim 1, wherein the controller is also configured to update a second word line during the second update cycle.

Citation Information

Patent Citations

  • Apparatus and method for counteracting memory attacks

    CN115705892A

  • Storage device and method of operating the same

    CN115995248A

  • Memory device and method for controlling row hammering

    CN116246667A

  • Semiconductor memory device and memory system including same

    CN116895312A

  • Semiconductor memory device including refresh control circuit and memory system

    US20230290399A1