Power tear protection in non-volatile memory (NVM)

By using global transaction logs and atomic flags in nonvolatile memory, the state loss problem caused by power tear is solved, achieving higher robustness and security.

CN120144047APending Publication Date: 2025-06-13NXP BV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411778410.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-13
Filing Date
2024-12-05
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

Existing nonvolatile memory (NVM) is prone to loss of state or undefined due to power tearing during write operations, resulting in device failure or dangerous operation.

Method used

Global transaction log (GTL) and atomic flags are used to achieve power tear protection. GTL ensures that the memory state can be reliably restored after power failure by storing the descriptor of each transaction and the corresponding TLE flag.

Benefits of technology

By reducing the number of atomic flags that need to be protected, the area occupancy and access time of memory is reduced, and the maintenance of atomic flags is simplified, improving the robustness and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120144047A_ABST
    Figure CN120144047A_ABST
Patent Text Reader

Abstract

A non-volatile memory (NVM) system includes a memory array partitioned into physical pages, control circuitry, and a global transaction log (GTL). Each physical page is configured to store a corresponding payload and corresponding metadata of the physical page. Each entry of the GTL is configured to store a transaction descriptor identifying a transaction and a corresponding physical page used by the transaction. Each entry also has a corresponding transaction log entry (TLE) flag. The control circuitry is configured to populate the entries of the GTL with each new transaction in a sequential order, and in response to completing storage of a transaction descriptor of a new transaction, program the corresponding TLE flag by switching a logic state of the corresponding TLE flag.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to non-volatile memory (NVM), and more particularly, to power tear protection in NVM. Background Art

[0002] In non-volatile memory (NVM), if a power loss occurs during a write operation (e.g., due to power tear), the state of the NVM may be lost or undefined. This can lead to faulty or dangerous operation of any device using such NVM. For example, the application of the device may result in improper operation, loss of sensitive information, security operation failure, etc. Tear may also be intentional, e.g., an attacker attempts to break the security mechanism by targeted power interruption. Therefore, in order to protect the content of the NVM and provide additional security, appropriate power tear protection is needed for those situations where power supply cannot be guaranteed.

[0003] Typically, such anti-tear methods rely on using multiple atomic flags associated with each NVM memory page, which identify the integrity of the page update action. It should be noted that an atomic flag is a flag that reliably causes a stable logic state (e.g., 0 or 1), or in the case of a tear, is a flag that can be reliably enhanced to the correct stable logic state. Generally, multiple bit cells must be used to implement the atomic behavior of the atomic flag. In current anti-tear implementations, each page in the NVM requires an atomic flag, so the number of atomic flags depends on the number of pages in the NVM. However, the area occupied by each atomic flag is relatively large. Additionally, in the case of using multiple atomic flags per page, each page update action requires multiple atomic flag updates, thus increasing the page access time. Additionally, the more atomic flags there are, the greater the time and complexity required to strengthen or maintain these flags when they become weak or unreliable. Therefore, there is a need to improve power tear protection. Summary of the Invention

[0004] According to a first aspect of the present invention, there is provided a non-volatile memory (NVM) system, comprising:

[0005] A memory array divided into physical pages, each physical page being configured to store a corresponding payload and corresponding metadata of the physical page;

[0006] Control circuitry; and

[0007] A global transaction log (GTL) having a plurality of entries, wherein each entry is configured to store a transaction descriptor that identifies a transaction and a corresponding physical page used by the transaction, each entry having a corresponding transaction log entry (TLE) flag, wherein the control circuitry is configured to:

[0008] Fill the entries of the GTL in sequential order with each new transaction, and

[0009] In response to completing storage of a transaction descriptor for a new transaction, program the corresponding TLE flag by toggling the logical state of the corresponding TLE flag.

[0010] In one or more embodiments, the transaction descriptor includes an opcode that identifies a memory transaction type and a physical page address that identifies the physical page.

[0011] In one or more embodiments, the memory transaction type includes a type selected from the group consisting of a page update transaction, a page allocation transaction, and a page release transaction.

[0012] In one or more embodiments, when the opcode of the transaction descriptor identifies the memory transaction type as the page update transaction, the transaction descriptor includes a first physical page address that identifies the physical page with the old information and a second physical page address that identifies the physical page with the new information.

[0013] In one or more embodiments, during startup of the memory system after a power-down, the control circuitry is configured to scan the GTL to find a discontinuity in the logical state of the TLE flags in order to identify a last transition entry (LTE) corresponding to the entry of the GTL that immediately precedes the discontinuity according to the sequential order.

[0014] In one or more embodiments, the TLE flag corresponding to the LTE has a different logical state than the successor entry of the GTL that immediately follows the discontinuity according to the sequential order.

[0015] In one or more embodiments, each TLE flag is implemented as an atomic flag, and the corresponding transaction descriptor of the LTE identifies the latest transaction, and the corresponding transaction descriptor of the latest transaction is confirmed to have been reliably stored in the GTL before the power-down.

[0016] In one or more embodiments, during the startup of the memory system, the control circuitry is further configured after identifying the LTE:

[0017] Identify any physical pages used by the latest transaction as exception pages, and

[0018] Store mapping information of the exception pages in a set of exception registers.

[0019] In one or more embodiments, the corresponding metadata of each physical page is configured to store the logical address of the physical page and a non-atomic mapping flag for indicating whether the physical page is mapped to the logical address or unmapped.

[0020] In one or more embodiments, during the startup of the memory system, the control circuitry is further configured to create a mapping table configured to store the associated mapping information of each mapped physical page of the array by using the metadata corresponding to the mapped physical pages or the set of exception registers, so as to obtain the associated mapping information.

[0021] In one or more embodiments, during the startup of the memory system, the control circuitry is further configured to:

[0022] create a mapping table by iteratively traversing each physical page address of the array, wherein for each physical page address, if the physical page address corresponds to an identified exception page, obtain the mapping status from the set of exception registers, otherwise obtain the mapping status from the non-atomic mapping flag of the corresponding metadata of the physical page address, wherein the mapping status indicates whether the physical page address is mapped or unmapped; and

[0023] for each mapped physical page address, store the mapping information of the physical page address into the mapping table.

[0024] In one or more embodiments, the control circuitry is further configured to:

[0025] enhance the TLE flag corresponding to the LTE in response to determining that the TLE flag corresponding to the LTE is weakly programmed; and

[0026] enhance the TLE flag corresponding to the successor entry in response to determining that the TLE flag corresponding to the successor entry is weakly programmed.

[0027] According to a second aspect of the present invention, there is provided a non-volatile memory (NVM) system, comprising:

[0028] a memory array divided into physical pages, each physical page being configured to store a corresponding payload and corresponding metadata of the physical page;

[0029] control circuitry; and

[0030] A global transaction log (GTL) having a plurality of entries, each entry being configured to store a transaction descriptor that identifies a page transaction and a physical page used by a page update transaction, each entry having a corresponding transaction log entry (TLE) flag, each corresponding TLE flag being implemented as an atomic flag, wherein the control circuitry is configured to:

[0031] Fill the next entry of the GTL with a new page transaction in sequential order,

[0032] After storing the transaction descriptor of the new page transaction into the next entry, confirm the new page transaction by toggling the logical state of the corresponding TLE flag, and

[0033] Terminate the new page transaction when the next page transaction after the new page transaction is received.

[0034] In one or more embodiments, the corresponding metadata for each physical page is configured to store the logical address of the physical page and a non-atomic mapping flag for indicating whether the physical page is mapped to the logical address or unmapped.

[0035] In one or more embodiments, during startup of the memory system after a power-down, the control circuitry is configured to scan the GTL to find a discontinuity in the logical state of the TLE flags in order to identify a last transition entry (LTE) corresponding to the entry of the GTL immediately preceding the discontinuity, and the transaction descriptor identification of the LTE is confirmed as the latest transaction that was in the GTL before the power-down but not yet terminated.

[0036] In one or more embodiments, during the startup of the memory system, the control circuitry is further configured, after identifying the LTE:

[0037] Identify any physical pages used by the latest transaction as exception pages, and

[0038] Store the mapping information of the exception pages into a set of exception registers.

[0039] In one or more embodiments, during the startup of the memory system, the control circuitry is further configured to:

[0040] A mapping table is created by iteratively traversing each physical page address of the array, wherein for each physical page address, if the physical page address is identified as an abnormal page, the mapping status is obtained from the set of abnormal registers, otherwise the mapping status is obtained from the non-atomic mapping flag of the corresponding metadata of the physical page address, wherein the mapping status indicates whether the physical page address is a mapped page or an unmapped page, and

[0041] For each mapped physical page address, the mapping information of the physical page address is stored in the mapping table.

[0042] In one or more embodiments, the control circuitry is further configured to:

[0043] Enhance the TLE flag corresponding to the LTE in response to determining that the TLE flag corresponding to the LTE is weakly programmed; and

[0044] Enhance the TLE flag corresponding to the successor entry in response to determining that the TLE flag corresponding to the successor entry is weakly programmed.

[0045] In one or more embodiments, when the transaction descriptor of the new page transaction identifies a page update transaction that updates the logical page mapping from an old physical page of the memory array to a new physical page of the memory array, the control circuitry is configured to terminate the new page transaction by:

[0046] Updating the non-atomic mapping flag of the corresponding metadata of the new physical page identified by the transaction descriptor of the new page transaction, and

[0047] Updating the non-atomic mapping flag of the corresponding metadata of the old physical page identified by the transaction descriptor of the old page transaction.

[0048] In one or more embodiments, the control circuitry is configured to roll back to the start entry of the GTL after each entry of the GTL has been filled.

[0049] These and other aspects of the invention will be apparent from and elucidated with reference to the embodiments described hereinafter. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] The invention is illustrated by way of example and is not limited by the accompanying drawings, in which like reference numerals indicate like elements. The elements in the figures are shown for simplicity and clarity and are not necessarily drawn to scale.

[0051] Figure 1A data processing system including a non-volatile memory (NVM) and an associated global transaction log (GTL) according to an embodiment of the present invention is shown in block diagram form.

[0052] Figure 2 The contents of the GTL over time according to an embodiment of the present invention are shown in tabular form.

[0053] Figure 3A and 3B The sequential steps of an example page update transaction over time are shown in tabular form.

[0054] Figure 4 The sequential steps of an example page transaction over time are shown in tabular form.

[0055] Figure 5 The contents of the GTL entries and physical pages of the NVM over time according to an embodiment of the present invention are shown in tabular form.

[0056] Figure 6 A method of using the GTL according to an embodiment of the present invention is shown in flowchart form.

[0057] Figure 7 A mapping operation according to an embodiment of the present invention is shown in flowchart form. DETAILED DESCRIPTION

[0058] Tear protection for the NVM ensures that the contents of the NVM are robust even in the case of a tear event where power is lost during NVM operation. That is, any event that causes a power-off or power interruption (whether intentional or unintentional) is a tear event. In one aspect, the anti-tear method for the NVM is implemented using a global transaction log that stores metadata information related to each ongoing content update transaction performed on the NVM and protects the stored information with an atomic flag. In this way, instead of using one atomic flag (or multiple atomic flags) for each block (e.g., page) of the NVM to protect the metadata associated with each NVM block, only one atomic flag is needed for each transaction in the log, so the number of atomic flags depends on the transaction log rather than the size of the NVM. Each atomic flag occupies a relatively large area, so it is desirable to reduce the number of atomic flags required. Atomic flags also need to be properly maintained or enhanced. In the previous example, all atomic flags for each block of the NVM needed to be enhanced or maintained, thus increasing the cost and complexity required. However, with the use of a global transaction log, the maintenance of atomic flags can be simplified.

[0059] Figure 1FIG. 0 shows a data processing system 10 that includes a processor 12, a non-volatile memory (NVM) 14 (which may also be referred to as an NVM system), and a volatile memory 24 coupled to a system interconnect 28. The data processing system 10 may correspond to any type of device used in different types of applications (e.g., in automotive applications, smart cards, etc.) and may thus be referred to as a device. In one embodiment, the data processing system 10 may be implemented as a system-on-chip (SoC). The volatile memory 24 may be any type of volatile memory, such as static random access memory (SRAM).

[0060] The NVM 14 includes a memory array 16 that may be divided into a plurality of memory blocks (referred to herein as pages or physical pages), a global transaction log (GTL) 18, and control circuitry 20 (also referred to as a controller 20). The controller 20 includes an exception register 22. The GTL 18 may also be referred to simply as the log 18. The GTL 18 is associated with the NVM 14 and may be stored in a storage circuitry that is part of the memory array 16 or a separate storage circuitry in the NVM 14 external to the array 16. It should be noted that in an alternative embodiment, the GTL 18 may alternatively be stored in a memory separate from the NVM 14 (e.g., a separate NVM). The NVM 14 may be implemented as any type of NVM, such as resistive random access memory (RRAM), magnetoresistive random access memory (MRAM), flash memory, electrically erasable programmable read-only memory (EEPROM), etc. The system interconnect 28 may be any type of interconnect, such as a bus, crossbar switch, fabric, etc. In an alternative embodiment, the data processing system 10 may be referred to as a memory system that includes the NVM 14, the controller 20, and the GLT 18, where the GTL 18 may be internal or external to the array 16 or may be external to the NVM 14. The controller 20 controls access to the array 16 and also controls access to the GTL 18 (e.g., controls the update entries of the GTL 18). In an alternative embodiment, separate controllers may be implemented for accessing each of the array 16 and the GTL 18.

[0061] The array 16 of the NVM 14 is divided into multiple pages. Each physical page is configured to store a corresponding payload (PL). In addition to the payload, each physical page also has corresponding mapping information, and the corresponding mapping information includes a logical address (LogicalAddr) mapped to the physical page and a corresponding non-atomic mapping flag (MUF) indicating the status of the mapping (i.e., whether the physical page is mapped or unmapped). Each MUF is a non-atomic flag that can be implemented as a single bit, which indicates that the page has been mapped when asserted and indicates that the page has not been mapped when negated. The non-atomic flag is vulnerable to tear events, which may cause the value of the flag to be uncertain and thus no longer valid or correct. The mapping information and MUF can be regarded as the metadata of the physical page, where the metadata may include additional corresponding information (such as a count value, an error correction code, etc.). Although the metadata is logically linked to the physical page, the metadata may not be stored in the same physical memory page. That is, the metadata can be stored in the same physical memory page or other locations within the NVM 14.

[0062] When performing a logical page update in the NVM 14, each information logical page (including the payload and the corresponding metadata) is updated at different physical locations, so that the old information is maintained until it is confirmed that the new information has been fully written. The old information can be maintained by, for example, writing the updated information to a new physical page. However, when writing new information, both the old information and the new information belong to the same logical memory block (i.e., both the old page and the new page are mapped to the same logical address). Once the MUFs of the old page and the new page are properly updated, they can be used to distinguish the old information from the new information. However, if the MUF is unreliable due to a tear event, for example, it is impossible to properly distinguish the old information from the new information. Therefore, in order to maintain proper operation, it is necessary to distinguish the old information and the new information, even after a tear event occurs, where the choice between the old information and the new information is always consistent. That is, at any given time, only one of the old page or the new page should be indicated as valid, and once the old page becomes invalid, it should not be restored to be valid after a tear event.

[0063] In one embodiment, the NVM 14 is able to distinguish old information from new information by using the GTL 18 to track any ongoing transaction. Each transaction log entry (TLE) of the GTL 18 is configured to store a TLE descriptor of a transaction (i.e., a page transaction), where the descriptor identifies the type of the transaction (e.g., using an opcode) and provides mapping information between a logical address and a physical address. The descriptor may include any number of parameters of the page transaction as needed (e.g., the physical address of the page involved in the page transaction). In some embodiments, one of the parameters also includes the logical address of the page transaction. Depending on the type of the transaction, the descriptor may also include additional information of the transaction. Each TLE of the GTL 18 also has a corresponding TLE flag, where each TLE flag is implemented with an atomic flag. In the case of each new transaction of the NVM 14, the next entry of the GTL 18 is filled, and when the corresponding atomic TLE flag is programmed for the filled entry, all the information in the TLE descriptor of the entry is considered stable and not subject to maintenance, thus ensuring a consistent mapping between the physical page and the logical page. The TLE flag of the GTL 18 can then be used to identify the last transaction entry (LTE) of the GTL 18 during the startup sequence after a power-down, where the LTE stores the latest transaction whose corresponding TLE flag was programmed before the power-down. Then, in addition to the metadata (e.g., MUF, logical address) stored in the physical pages of the NVM 14, the mapping information stored in the identified LTE can be used to generate an accurate mapping table for all the pages of the NVM 14, even after a tear event.

[0064] Thus, it should be noted that each page of the array 16 includes a corresponding non-atomic MUF, but does not include a corresponding atomic TLE flag. In this way, not every page of the array 16 needs an atomic flag, and only each entry in the GTL 18 needs an atomic flag. Therefore, fewer atomic flags than non-atomic flags are required to implement the NVM 14 securely. As will be described in more detail below, the atomic TLE flags in the GTL 18 provide sufficient information to distinguish new pages from old pages during page updates, even if a tear event causes the MUFs of the old pages and the new pages to be incorrect or invalid.

[0065] As described above, each entry of the GTL 18 stores a corresponding atomic flag. The atomic flag can be programmed to a logical state by setting the atomic flag to a logical level one or clearing it to a logical level zero. As used herein, an "atomic flag" refers to a flag that is programmed (i.e., set or cleared) in a reliable manner such that there is no risk of an indeterminate pseudo-random flag value being caused by a tearing event. That is, the atomic flag has two stable states and a transition state between the two table states, and after a tearing event, the atomic flag can be reliably detected and brought into one of the stable states. Thus, for an atomic flag, a weak clear flag or a weak set flag that may be misread as a logical one or a logical zero, respectively, in a pseudo-random manner should be reliably detected as being weakly programmed (i.e., weakly cleared or weakly set, respectively), and should then be able to be accurately enhanced to be strongly programmed (i.e., strongly cleared or strongly set, respectively). However, during the enhancement process, a strong clear flag or a strong set flag should not be changed to its opposite value.

[0066] In one embodiment, an atomic flag can be implemented using multiple bit values (i.e., multiple non-atomic flags or multiple memory cells), where the memory controller may need to perform many different sequential operations to set or clear the atomic flag. In one example, the atomic flag is implemented using 2 memory bits, which can provide four states (0-0, 0-1, 1-0, and 1-1), also referred to as conditions. The states can be defined as follows: 0-0 indicates that the atomic flag is in an invalid or uninitialized state, 0-1 indicates that the atomic flag has been cleared (i.e., is at a logical level 0), 1-0 indicates that the atomic flag has been set (i.e., is at a logical level 1), and 1-1 indicates that the atomic flag is unknown (i.e., is "X"). During operation, the controller 20 performs a series of operations to set or clear the flag. For example, to set the flag, the controller 20 is configured to sequentially set each memory cell in a pair of memory bits such that the first memory cell in the pair of memory bits has been fully programmed (i.e., set to a condition associated with an analog value such as voltage, current, or resistance, the analog value being associated with whether the desired state is a set state or a cleared state) before the controller 20 modifies the second memory cell in the pair of memory bits. It should be noted that even though the controller 20 can perform multiple sequential operations to set or clear the flag, this flag is considered to be "atomic".

[0067] Thus, in the above example, when programming the atomic flag, the bit set to 0 is first set to 1, and then the other bit is cleared to 0. In this way, setting the atomic flag involves updating a pair of memory bits from 0-1 to 1-0, which is performed through the following series of operations (steps): 0-1 → x-1 → 1-1 → 1-x → 1-0. That is, first, the 0 bit (i.e., the first bit of the pair) is set to 1, and next, the 1 bit (i.e., the second bit of the pair) is cleared to 0. Similarly, clearing the atomic flag involves updating a pair of memory bits from 1-0 to 0-1, which is performed through the following series of operations (steps): 1-0 → 1-x → 1-1 → x-1 → 0-1. Again, first, the 0 bit (i.e., the second bit of the pair) is set to 1, and next, the 1 bit (i.e., the first bit of the pair) is cleared to 0. Alternatively, a clear-then-set order can be implemented, where the 1 bit is first cleared to 0 and then the other bit is set to 1. In this alternative embodiment, 1-1 can indicate an invalid or uninitialized state, and 0-0 can indicate that the atomic flag is unknown.

[0068] If programming of the atomic flag is interrupted due to a tearing event (tear), only one of the pair of memory bits may be in an indeterminate condition (i.e., be x), because the other bit of the pair of memory bits can only be updated after the first update is successfully completed. When reading the value of the atomic flag, the "x" state of the memory cell can be read as a 0 value or a 1 value, depending on whether the value of the memory cell is read as above or below the threshold of the cell. Thus, the potentially unstable condition in the case of a tear is when the pair of bits is in x-1 or 1-x, which can be read as 0-1 or 1-0, respectively, or as 1-1.

[0069] If the controller 20 reads the atomic flag x-1 as 0-1, the controller 20 interprets the atomic flag as being in its cleared state (i.e., logic level 0). This is correct because the tearing event occurred during the first step of the flag setting operation (e.g., 0-1 to x-1) or during the second step of the flag clearing operation (e.g., x-1 to 0-1). If the controller 20 reads 1-x as 1-0, the controller 20 interprets the atomic flag as being in the set state (i.e., logic level 1). This is correct because the tearing event occurred during the second step of the flag setting operation (e.g., 1-x to 1-0) or during the first step of the flag clearing operation (e.g., 1-0 to 1-x). Additionally, if the controller 20 reads x-1 as 0-1 or 1-x as 1-0, these (corresponding to the weak flag) unstable conditions can be enhanced to clean 0-1 or clean 1-0 by respectively clearing the memory cell in the pair from "x" to 0 or setting it to 1.

[0070] However, if the condition x - 1 or 1 - x is read as 1 - 1, the controller 20 determines that the atomic flag is in an unknown state. This condition indicates the occurrence of a tearing event because the 1 - 1 condition can only occur when a tearing event interrupts a programming operation. Therefore, if the said condition is read as 1 - 1, the status of the bits needs to be parsed all the time, and various methods can be used to implement the parsing. In one example, the controller 20 can perform a margin check to determine which memory cell in the pair is the weaker bit and clear the said bit to 0 so that the pair of bits is read as 0 - 1 or 1 - 0. The weaker bit is the memory cell in the pair whose read signal (e.g., read voltage or read current) is closer to the threshold of the memory cell.

[0071] Thus, in this way, the atomic flag will always be reliably read as set (to logic level 1) or cleared (to logic level 0), even when a tearing event occurs during the programming of the atomic flag, causing one of the bits in a pair of bits of the atomic flag to be in the "x" state. That is, the occurrence of a tearing event does not produce an indeterminate pseudo - random flag value. It should be noted that in alternative embodiments, each atomic flag can be implemented with more than just two bits. For example, some embodiments of atomic flags are described in U.S. Publication No. 20230315325A1. However, other embodiments of atomic flags can also be used.

[0072] It should be noted that, compared with atomic flags that may require multiple memory bits to implement and multiple operations to program, non - atomic flags can be implemented with a single memory bit (where the single memory bit can be either logic level one or logic level zero). However, if a tearing event occurs during the writing of a non - atomic flag, the resulting value may be indeterminate. In addition, it should be noted that setting or clearing a non - atomic flag can be done with one operation, while as described above, setting or clearing an atomic flag may require multiple operations. Also, as described above, atomic flags need to be maintained to ensure that the atomic flag safely maintains its state. In this way, an atomic flag determined to be weakly programmed can be enhanced to strongly programmed.

[0073] Figure 2GTL 18 according to an embodiment of the present invention is shown in tabular form. GTL 18 tracks a single ongoing transaction, where only one transaction can occur at a time. Each entry of GTL 18 is configured to store a descriptor of the transaction and a corresponding TLE flag (implemented as an atomic flag). In the illustrated embodiment, each TLE flag is shown as a logical one or a logical zero, reflecting the atomicity that can be reliably resolved into one state or the other. That is, as described above, the state "x" may occur due to a tear event during flag update. However, it is assumed that this can be reliably detected and resolved when scanning GTL 18 for LTEs (including the final enhanced LTE flag) at system startup (during the startup sequence).

[0074] Figure 2 Shows how GTL 18 is updated over time for 8 consecutive transactions (TR1 - TR8). For each transaction, the TLE descriptor of the entry is updated before toggling the corresponding TLE flag to mark the entry as valid. A tear event during descriptor update does no harm because the entry is not used (not considered reliable to use) until the TLE flag is toggled. A tear event during TLE flag update also does not pose a problem because the TLE flag update is atomic. It should be noted that each transaction causes only one TLE flag to be toggled.

[0075] In the illustrated embodiment, each transaction within GTL 18 is identified by TRn, where "n" is an integer value greater than zero to distinguish the transactions. As will be described in more detail below, each transaction can refer to a memory transaction or a page transaction (also referred to as a page operation), such as a page update transaction, a page allocation transaction, a page release transaction, or any other available page transaction. The descriptor of the transaction can also be referred to as the command of the transaction and can include the corresponding opcode of the command. The illustrated embodiment includes only four transaction entries (identified from top to bottom as log entry 0 - log entry 3, also referred to as entry 0 - entry 3 or TLE 0 - TLE 3, where the values 0 - 3 can be referred to as the index of the entry). Each entry includes a TLE descriptor section, which is configured to store the corresponding TLE descriptor of the transaction and the corresponding TLE flag. As time increases from the left column (column 100) to the right column (column 116), Figure 2 each of the columns 110 - 116 shown corresponds to the example content of entries 0 - 3 at different time points. Since each column corresponds to time, columns 100 - 116 can also be referred to as time 100 - time 116, where the time does not need to represent time slots of equal duration (i.e., they do not need to be equally spaced in time).

[0076] In one embodiment, the TLE flags are all initialized to zero. Alternatively, the TLE flags can be initialized to one. In the illustrated embodiment, all TLE flags are initialized to zero, and thus, at time 100, the TLE flag for each of entries 0 - 3 is zero. At time 101, a first transaction TR1 is initiated (e.g., by processor 12). The descriptor of TR1 is written to the descriptor portion of entry 0. After the descriptor is fully written (fully programmed into entry 0), the corresponding TLE flag toggles (in this case, set to logic 1 since it was previously logic 0). Thus, at time 102, the TLE flag of entry 0 is set to logic 1. Similarly, at time 103, a second transaction TR2 is initiated and the descriptor of TR2 is written to the descriptor portion of entry 1. After the descriptor is fully written, the corresponding TLE flag toggles (set to logic 1 at time 104). Thus, for each new transaction, the next sequential entry of GTL 18 is populated by first writing the descriptor to the descriptor portion of the entry and then toggling the corresponding TLE flag once done. As will be described in more detail below, each transaction tracked by GTL 18 includes two parts: part a) update (e.g., programming the payload and metadata in NVM and programming the entries of GTL), and part b) termination (e.g., updating the MUF in NVM). The corresponding TLE flag toggles between the two parts, where the update part of the transaction is not acknowledged (i.e., considered complete) until the corresponding TLE flag toggles. In this way, each transaction can be described in the following order: part a, update of the TLE flag, followed by part b. In one embodiment, as part of programming the metadata, the logical address is updated in NVM in part a. However, in an alternative embodiment, as part of termination, instead, the logical address is updated in part b, along with updating the MUF in NVM. However, in this alternative embodiment, the logical address is stored as part of the programmed entry of GTL in part a.

[0077] Still referring to Figure 2 , when a tear occurs, the last transaction entry (LTE) of GTL 18 identifies which transaction was in progress when the tear occurred. More specifically, the LTE corresponds to the last valid entry that has been acknowledged but not yet terminated. After a tear event, the LTE can be identified by determining the discontinuity of the TLE flags, since the determination of the discontinuity determines the last transaction whose corresponding TLE flag toggled (thereby acknowledging the transaction). In Figure 2In it, below each column, the corresponding LTE is provided, assuming that a tear event occurs at this time. For example, if the tear event occurs at time 104, the LTE is identified as entry 1 because there is a discontinuity in the TLE flag between entry 1 (TLE flag = 1) and entry 2 (TLE flag = 0) at this time, and the discontinuity can be found by scanning the TLE flags in the column from top to bottom. Therefore, TR2 has been confirmed but not terminated. If the tear event occurs later, for example, at time 105, the LTE is also identified as entry 1 because there is still a discontinuity in the TLE flag between entry 1 and entry 2. Even though TR3 also starts at time 105, it has not been confirmed (because its corresponding TLE flag has not switched). Due to the discontinuity occurring between entry 2 and 3 at any of these times, the tear event at time 106 or 107 will cause the LTE to be identified as 2. Since the identified LTE is considered to be confirmed, the TLE descriptor of the LTE is considered to be reliable. The determination and use of the LTE flag after a tear event will be described in more detail below. (In addition, in the last entry corresponding to entry 3 in the embodiment shown in Figure 2 in the "init." indicates that the TLE descriptor value has been initialized and is therefore valid to indicate "no transaction command". In this way, if it is indicated as LTE, entry 3 is a valid entry.)

[0078] It should be noted that in the example of the TLE flag implemented with multiple bits, switching the logical state of the TLE flag requires a series of operations to transition from one state to another, as described above. However, even if a tear event occurs during the switching of the TLE flag, the TLE flag will always be read or parsed as a stable state.

[0079] Note that, according to the logical order of the entries, the GTL 18 is filled sequentially with each new transaction and is updated only in one direction (e.g., in the illustrated embodiment, from entry 0 to entry 3, or top - down). Each time a new transaction starts and utilizes the next available entry in the GTL 18, note that the previous entry (created in response to the previous transaction) is considered invalid. In this way, the GTL 18 includes only one valid entry at a time. In the illustrated embodiment, the entries of the GTL 18 are filled sequentially according to increasing index values (e.g., entry 0, then entry 1, then entry 2, then entry 3). In the illustrated embodiment, the GTL 18 is implemented as a rolling log, where the entry filled sequentially after entry 3 rolls back to entry 0. (Alternatively, the entries of the GTL 18 can be filled sequentially according to a different logical order of the entries, e.g., according to decreasing index values.) In the illustrated embodiment, once the GTL 18 is full (and thus rolls back to entry 0 for a new transaction), the direction of the TLE flag switch is reversed (e.g., from switching from 0 to 1 becomes switching from 1 to 0, and vice versa). For example, once each entry of the GTL is filled sequentially from the start entry to the last entry, and the corresponding TLE flag is switched (programmed) by flipping in one direction, then filling the GTL 18 wraps back to the start entry, and the corresponding TLE flag is switched (programmed) by flipping in the opposite direction. This avoids the need for special maintenance of the TLE flags due to the necessary operation of clearing all TLE flags (or setting all TLE flags), which although required may itself be affected by tearing. In one embodiment, the filling of the next sequential entry and the switching of the TLE flag can be performed by the controller 20. Additionally, although only 4 entries are shown, the GTL 18 can include any number of entries.

[0080] Figure 3A and 3B The example logical page update transaction is shown in more detail in tabular form. As discussed above, each transaction "n" includes an update portion (portion a) that updates the corresponding TLE flag and a termination portion (portion b). First referring to Figure 3A , the rows are labeled 310a - 344a from top to bottom, where each row includes the sequential steps of the page update transaction occurring in increasing time order (where each row can take a different amount of time as needed). The thick line separates the previous transaction "n - 1" (corresponding to rows 310a - 324a) from the subsequent transaction "n" (corresponding to rows 330a - 344a).

[0081] First referring to Figure 3ATransaction "n" updates the payload (writes the PL to a new page in the NVM) at line 330a. In addition to updating the payload, metadata can also be updated by writing the logical address to a new page in the NVM. Next, at line 332a, the TLE descriptor is written to the next entry in the GTL 18. The TLE descriptor of the transaction includes the opcode of the page update transaction and two corresponding parameters P0 and P1, where P0 indicates the physical page address of the old page being updated, and P1 indicates the physical page address of the newly updated page. P0 and P1 correspond to the mapping information for this transaction. (If the metadata of the new page is not updated with the logical address, the logical address will also be included as part of the TLE descriptor written to the GTL 18.) At line 334a, the mapping lookup table (LUT) 26 is updated. The mapping LUT 26 (also known as the mapping table) can be used by the processor 12 to convert the logical address into a physical address and can be stored in the memory 24 of the system 10. At line 336a, the transaction is confirmed by toggling the corresponding TLE flag. Thus, lines 330a to 336a correspond to the update part (part a) of the transaction. At this point, the transaction is confirmed in the GTL 18 (meaning the TLE descriptor is reliably stored), but the transaction has not yet terminated. That is, since the LUT 26 is volatile, the mapping information and MUF should be persistently stored in the NVM 14.

[0082] For a page update, the new page must be mapped and the old page must be unmapped. Thus, at line 338a, the new page is mapped by asserting the corresponding MUF of the new page. Mapping the new page can also include updating the mapping information of the new page with the logical page address (performed before toggling the TLE flag if not already done at line 330a). In this case, it should be noted that the logical address can be obtained from the TLE descriptor of the LTE. At line 340a, the old page is unmapped by clearing (i.e., negating) the corresponding MUF of the old page. At line 342a, any other metadata is updated in the new page if needed. These mapping steps (and the update of any other metadata if needed) terminate the transaction such that the mapping information is now stored in the page NVM 14. Thus, lines 338a to 342a correspond to the termination part (part b) of the transaction.

[0083] Since the mapping information is backed up in the GTL 18 (backed up as P0 and P1), the termination of the transaction can be repeated if needed, such as when recovering from a tear event. However, without an additional flag to confirm the termination, a tear event cannot be reliably detected during the update of the NVM (during part b of the transaction). For example, if the transaction actually terminates before toggling the TLE flag, the backed-up mapping information in the TLE descriptor has not been confirmed, and a tear event during the termination part will cause inconsistent mapping. Thus, in Figure 3AIn the embodiment of, an additional atomic flag (referred to as a termination flag) is required to confirm the termination of the assertion at line 344a, thus confirming the termination of the transaction (part b). (Similarly, for transaction n-1, lines 310a-314a correspond to part a of the transaction, line 316a corresponds to toggling the TLE flag, lines 318a-322a correspond to part b of the transaction, and the termination is confirmed by asserting the corresponding termination flag at line 324a.) However, to support Figure 3A transactions, GTL 18 may require two atomic flags per entry, which is costly.

[0084] Figure 3B illustrates a page update transaction, which is similar to Figure 3A the page update transaction of, but does not require an additional termination flag. In Figure 3B , the lines are labeled 310b-344b from top to bottom, where each line includes sequential steps of a page update transaction occurring in increasing order of time from top to bottom (where each line may take a different amount of time as needed). As described above with reference to Figure 3A , once the corresponding TLE flag is toggled by using the backup mapping information in the confirmed TLE descriptor, the termination part (part b) of the transaction can be repeated. Thus, it is possible to defer the termination of the transaction until the next transaction starts, since this next transaction will utilize the next new entry of GTL 18, thus invalidating the previous entry. By not immediately terminating the last transaction after toggling the corresponding TLE flag, there will always be an un-terminated but confirmed transaction (i.e., a transaction with a confirmed TLE descriptor whose corresponding TLE flag has been toggled). At startup, the mapping information for creating the mapping LUT 26 can be retrieved from NVM 14 for all pages except for the pages that are part of the last transaction interrupted by a tearing event (thus referred to as exception pages). For these exception pages, the mapping information is obtained from the LTE of GTL 18, corresponding to the last valid GTL entry. The LTE of GTL 18 is determined at startup by identifying the discontinuity of the TLE flag.

[0085] Still referring to Figure 3B, before starting a new transaction n (at line 330b), the previous transaction n-1 must first be terminated (by the steps in lines 318b-322b corresponding to part b of the previous transaction n-1 such that the mapping information resulting from transaction n-1 is persistently stored in a page of the NVM 14). If this transaction experiences a tear, the next subsequent transaction (upon restart or later) will re-perform the termination of the previous transaction n-1 (part b). If no tear occurs, the execution of transaction n continues at lines 330b-334b (corresponding to part a of transaction n), and the confirmation of transaction n can be achieved by toggling the corresponding TLE flag (at line 336b). Similarly, the termination of transaction n is postponed (corresponding to lines 338b-342b) until the next transaction n+1 is requested. Thereby, termination does not require a dedicated confirmation flag, such as Figure 3A 's termination flag. Instead, as Figure 3B shows, only a single atomic TLE flag protects both the termination of the previous transaction and the confirmation of the current transaction. That is, Figure 3B 's TLE flag for transaction n in Figure 3A protects both the termination of transaction n-1 and confirms transaction n, different from Figure 3A 's TLE flag for transaction n that only confirms transaction n, and thus an additional termination flag is required to protect the termination of transactions (e.g., transactions n-1 and n).

[0086] During the startup sequence after a tear event, the GTL 18 can be sequentially scanned (e.g., scanned vertically from top to bottom as described above in Figure 2 ) through the entries of the GTL 18 to determine the LTE that identifies the last confirmed (i.e., non-torn) transaction. This can be done by detecting a discontinuity in the value (logical state) of the TLE flag when sequentially scanning the entries. (To accelerate the search, other algorithms such as binary search can be used instead of sequential scanning.) For example, referring back to Figure 2 , if a tear event occurs during writing TR3 to the descriptor part of log entry 2 (at time 105), then when scanning the GTL 18, the first discontinuity of the TLE flag can still be detected between entry 1 and entry 2. Entry 1 corresponds to the entry of the GTL 18 immediately before the discontinuity, and entry 2 corresponds to the entry immediately after the discontinuity. In this example where the flag is initially set to zero, the discontinuity corresponds to the TLE flag changing from 1 to 0 between the entries. However, since the TLE flag toggles with each transaction, in the case where all TLE flags have been toggled to 1 (or if they are initially set to 1), the discontinuity will instead correspond to the TLE flag changing from 0 to 1 between the entries.

[0087] In Figure 2In this example, in the case where a tear event causes a discontinuity in the TLE flag between entry 1 and entry 2, it is known that the LTE corresponds to the current information stored in the TLE descriptor portion of entry 1. As will be described in further detail in the examples below, since it is known that TR2 is confirmed (due to the subsequent switching of the corresponding TLE flag in entry 1), the descriptor information of TR2 stored in entry 1 is trustworthy and reliable and can be used to identify the correct mapping of the logical address to the appropriate physical address. However, even though TR2 is confirmed, TR2 can also be terminated at any later time as long as it occurs before filling the next entry of GTL 18 with the next transaction and switching the corresponding TLE flag. Therefore, when a discontinuity in the TLE flag between two entries is found during the scan of GTL 18, it is known that the first of the two entries (i.e., the entry immediately before the discontinuity) is the LTE that accurately reflects the descriptor information of the last transaction. As another example, if a tear event occurs after switching the TLE flag of entry 2 but before switching the TLE flag of entry 3 (e.g., at Figure 2 time 107), it is known that entry 2 (i.e., the entry immediately before the discontinuity) corresponds to the LTE, and the current information stored in the TLE descriptor portion of entry 2 describes the last confirmed transaction (e.g., Figure 2 TR3 in

[0088] ). Additionally, during each startup, after identifying the LTE, if it is determined to be weak, the TLE flag of the LTE and the TLE flags in the subsequent entries of the LTE (i.e., the subsequent flags) can be strengthened. A tear event can affect the atomic flag in different ways. In one case, the atomic flag may have been switched but is still weak. For example, the atomic flag of the LTE may be a weak flag after switching and thus needs to be maintained. In another case, the atomic flag may still be in its old logical state but is already weak. For example, the atomic flag of the subsequent entry may have started to switch but not successfully, which means the subsequent flag may also need to be maintained. However, by construction, only two atomic flags are checked for maintenance after a power cycle (e.g., during a restart), which are the atomic flag corresponding to the LTE and the atomic flag corresponding to the subsequent entry of the LTE, because one of these two atomic flags may be affected by a power loss. Compared with using multiple atomic flags for each page of NVM instead of having GTL 18, only two atomic flags need to be checked and maintained after each power cycle, which not only simplifies the startup process but also saves time, where after each power cycle, each of the multiple atomic flags in each page needs to be checked and may be strengthened.

[0089] Figure 4An example flow for performing various page transactions is shown in tabular form, including page update 402, page allocation 404, and page release 406, where each flow shows the sequential steps of transaction n in rows 410 - 422 in increasing order of time from top to bottom (where each row may take a different amount of time as needed). First referring to Figure 4 page update 402 in the first set of columns of Figure 3B , the steps in rows 410 - 416 are the same as the steps shown in the lower part (rows 330b - 336b) of

[0090] . The steps of page update 402 in rows 410 - 414 correspond to part a of transaction n that is executed directly after the termination of the previous transaction n - 1. The termination steps of page update 402 in rows 418 - 422 correspond to part b of transaction n and are postponed until transaction n + 1 is requested. Figure 4 Next referring to page allocation 404 in the second set of columns of Figure 4 , page allocation 404 can be considered a sub - case of page update 402 where there is no old page / previously mapped page. Therefore, no unmapping is required. In this case, unlike row 420 of page update 402, "unmap old page" is not performed for page allocation 404. Similarly,

[0091] Figure 5 page release 406 in the third set of columns of Figure 5 is also a sub - case of page update 402 where there is no new page. Therefore, unlike row 410 of page update 402, no payload update is performed for page release 406. Additionally, unlike row 418 of page allocation 402, no new mapping information is written to the pages of NVM 14. In this case, it should also be noted that the LUT update for page release 406 in row 414 is different in that instead of replacing the old mapping of the LUT entry with a new mapping, the LUT entry becomes invalid. The newly allocated page (updated with a new payload as in row 410 of page update 402 and page allocation 404) can be any unused (i.e., unmapped) physical page of NVM 14. The old page (the page that is unmapped as in row 420 of page update 402 and page release 406) becomes an unused page that can be used in any future transaction. Figure 5Also shown is the TLE flag of the next (subsequent) entry of the entry currently being filled, and the next (subsequent) entry will be filled with transaction n+1. The portions of physical pages A and B shown include the corresponding payloads, logical page addresses, other metadata (if any), and the corresponding MUF (i.e., the non-atomic mapping flag reflecting the mapped state). The logical page with logical page address LogAddrX is located in physical page A (also referred to as NVM page A or simply page A), and physical page A includes a payload, referred to as PLA. Due to page updates, a new payload, referred to as PLB, is written to physical page B (also referred to as NVM page B or simply page B). For Figure 5 the example, assume that the TLE flags of GTL 18 are all initialized to zero such that when toggling the TLE flag, the TLE flag is updated to one.

[0092] Figure 5 Each row of reflects the data stored in the current entries of GTL 18, page A, and page B. The thick line boxes are used to highlight the updates performed in each row. In Figure 5 if transaction n tears during an update, any stored data written within parentheses reflects the data that is ignored (whether the data is valid or invalid). That is, the parentheses are used to indicate an irrelevant value (since the information may be lost).

[0093] Figure 5 Starting with the start condition at line 530, where the logical page is stored in page A (as PLA), all relevant metadata (logical page address, other metadata, and MUF) is valid, and page B is assumed to be an idle (unmapped) page, which is selected as the target for the updated data. It should be noted that page B may still contain valid metadata (e.g., other metadata and MUF). As the first step of line 530, as highlighted by the thick line box, the new payload is written to page B as PLB, and the logical page address is written to the metadata of page B as LogAddrX. It should be noted that other metadata can also be written to the metadata of page B or remain valid, as Figure 5 shown in the column "Other Metadata" of. Metadata updates can all be considered an extension of payload updates, where the metadata can be updated in parallel with the payload or in any sequential order relative to the payload. If a tear occurs, any changes to page B will not be recognized because page B does not contain any valid / mapped payload, and interrupted updates to the payload or logical address will be ignored.

[0094] Next, at line 532, the TLE descriptor of the next entry of the GTL 18 is programmed with the appropriate opcode of the page update transaction and the physical page addresses of pages A and B (P0 and P1 respectively), as highlighted by the thick line box. (It should be noted that other metadata can also be stored in this next entry, such as a backup of optional metadata.) It should be noted that this data can be programmed into the GTL 18 in any order or in parallel. If a tear occurs, the TLE descriptor of this entry will be ignored because the corresponding TLE flag has not been toggled yet. (At line 534, the LUT 26 is updated, but no update occurs in the GLT 18 or the array 16.) Next, at line 536, the corresponding TLE flag of the filled entry is updated (i.e., toggled), which confirms a successful update. Although the LUT update is shown as occurring at line 534, it can also occur earlier as long as it is completed after a successful write to the PLA. The LUT update can also occur after the corresponding TLE flag is toggled. Since the LUT 26 is in volatile memory, it must be recreated after any tear event at any time. The toggling of the corresponding TLE flag at line 536 verifies the TLE descriptor and is the last non-postponed step of transaction n.

[0095] As previously described, in an alternative embodiment, after toggling the corresponding TLE flag (at line 536), the logical address in page B (at line 530) can alternatively be updated later (along with other metadata). In this case, this information should be backed up as part of the corresponding TLE descriptor in the TLE entry in the GTL 18. However, updating the logical address of page B before toggling the corresponding TLE flag has the advantage that the corresponding TLE descriptor stored in the GTL 18 does not need to include the logical address. This can reduce the storage space required for each entry in the GTL 18 and reduce memory access. This is the case for any metadata updated in page B before toggling the corresponding TLE flag (the toggling confirms this updated metadata in page B), and less information needs to be backed up as part of the corresponding TLE descriptor. It should be noted that in other alternative embodiments, any information in page A, such as the "other metadata" of page A, can be processed in a similar manner to the "other metadata" of page B. For example, any or all of the "other metadata" of page A can also be stored as part of the TLE descriptor in the TLE entry for backup until termination is completed by the toggling of the next TLE flag (at line 548). However, storing more information into each TLE entry increases the storage space required for each entry in the GTL 18.

[0096] Line 538 can correspond to any amount of time and can include any number of restarts (where restarts can occur for reasons other than tear events). At startup, the page mapping for creating the mapping LUT 26 in the NVM 14 will be derived from the metadata of all pages except those pages marked as exceptions by the TLE descriptor of the LTE (which will be the entry confirmed at line 536). These two pages are processed according to the opcode of the TLE descriptor of the LTE. Thus, within the LUT 26, page B is mapped while page A is not mapped. In Figure 5 this is reflected by removing the parentheses from the PLB and adding parentheses to the PLA in line 536 (and the lines below). Since both of these pages are exceptions once the TLE flag is toggled, the other metadata for these two pages (at lines 540 - 546) is also considered no longer trustworthy and will be updated in the deferred termination step of transaction n. A backup of the relevant metadata can be retrieved from the TLE descriptor of the LTE.

[0097] At lines 540 - 544, the termination steps of transaction n are performed. This includes asserting the MUF of page B (line 540), unmapping the old page by clearing the MUF of page A (line 542), and updating the metadata in page B (line 544). These steps can be performed at any time and in any order before the start of transaction n + 1, and if a tear occurs, these steps can all be repeated due to the confirmed data stored in the TLE descriptor of the LTE. In the illustrated embodiment, it should be noted that when the next transaction n + 1 is requested, the termination of the transaction (e.g., lines 540 - 544) will be initiated. Only when the termination is successful and there is no interruption will transaction n + 1 (with the sequential operations typically shown at line 546) proceed to the TLE flag update (at line 548), where the TLE flag of the next entry (i.e., the successor entry) of the GTL 18 is toggled (as shown in column 550, corresponding to the TLE flag of the next sequential entry in the GTL 18). With the successful update of this next TLE flag, the previous TLE descriptor will become invalid. Thus, at startup after this, the mapping information for page B and the unmapping information for page A are retrieved from the metadata sections of pages A and B in the NVM 14 (for this, the parentheses are removed from the appropriate metadata at line 548). It should be noted that in an alternative embodiment, there may be no "other metadata" present or used in the NVM 14, in which case the operation at line 544 is not required. It should also be noted that in an alternative embodiment, the "other metadata" can include LogAddrX, in which case LogAddrX is not written to page B at line 530 with the payload update but is updated as part of the termination of transaction n at line 544.

[0098] In summary, at any time during the execution of transaction n, a tear event may occur, where any bracketed information may be lost or unreliable. If the tear event occurs before the TLE flag is updated, transaction n, including the termination of transaction n-1, is not visible to the system. However, once the TLE flag is updated, transaction n is confirmed and valid. The mapping information of the LUT will come from the corresponding TLE descriptor of LTE until the next transaction n+1 is confirmed (which also confirms the successful termination of transaction n).

[0099] As described above, the allocation page transaction and the release page transaction can be regarded as a sub-case or variant of the page update transaction. Therefore, for each of the allocation page transaction and the release page transaction, Figure 5 The description provided in the appropriate section of the illustrated page allocation transaction also applies to an allocation page transaction or a release page transaction. It should also be noted that other opcodes for other page transactions may also be used. For example, after initialization of the GTL 18, when there are no previous transactions, no pages are indicated as abnormal (i.e., as abnormal pages), and no termination steps are required, a "no operation" transaction may be useful.

[0100] To clearly describe Figure 5 As a page update for transaction n, the termination steps (lines 540-544) are drawn as belonging to transaction n, but will be performed as initial steps for any next transaction n+1. In the illustrated embodiment, after both MUFs are updated for transaction n (in lines 540 and 542), transaction n+1 is received as reflected at line 546. At this point, the descriptor is stored in the next entry ( Figure 5 18). This includes writing the opcode for the "next transaction entry" and information (if necessary) to P0 and P1. Once the descriptor is written to the next entry of GTL 18, the TLE flag of transaction n+1 is toggled (here, to a logic level 1), as reflected in row 548, column 550. At this point, the previous transaction n is considered terminated, wherein any subsequent tear events during the execution of transaction n+1 will not result in re-execution of any portion of transaction n, but will result in re-execution of portions of transaction n+1 using the information stored in the corresponding confirmed descriptor portion stored in GTL 18. In addition, when transaction n is completed (i.e., closed), it is known that the relevant data and metadata (including mapping information and MUF) in pages A and B are valid.

[0101] It should be noted that in the above embodiments, the operations of each page transaction, including updating the GTL 18, may be performed by the controller 20 or the processor 12. Similarly, scanning and searching for discontinuities to identify LTE may also be performed by the controller 20 or the processor 12.

[0102] Figure 6 Method 600 of using GTL 18 at startup of system 10 is shown in flowchart form in accordance with one embodiment of the present invention. At startup (602) of system 10, method 600 begins with a search (604) of GTL 18 to identify the last valid transaction entry (i.e., LTE). This can be a startup upon power-up, for example, after a tear event. The search identifies the LTE by looking for a discontinuity in the sequentially scanned TLE flags, as described in the example above. For example, GTL 18 can be scanned sequentially to detect a discontinuity. In another embodiment, a binary search can be implemented to find the discontinuity. When a discontinuity is found, the last entry in GTL 18 that is exactly before the discontinuity is identified as the LTE (where the TLE flag of the LTE and the TLE flag of the next entry immediately following the LTE store opposite logical states). In one embodiment, in the case where all TLE flags are the same and there is no discontinuity (e.g., after initialization or when writing the last TLE flag before reversing the switch to the opposite direction), the last entry in GTL 18 can be identified as the LTE. In the case of a tear event, the LTE corresponds to the transaction that was confirmed but not yet terminated when the tear event occurred. Figure 2 Once the TLE is identified, the strength of the TLE flag of the LTE is checked (606). If it is determined at decision diamond 608 that the TLE flag is weak, the TLE flag is enhanced (610) to make it reliable before proceeding. After the enhancement, or if the TLE flag is not determined to be weak, the strength of the TLE flag of the next (i.e., successor) entry is checked (612). If it is determined at decision diamond 614 that the TLE flag is weak, the TLE flag is enhanced (616). The TLE flags of successor entries are also checked and conditionally enhanced because a transaction may tear when switching the TLE flag of a successor entry, where the TLE flag may become weak but not fully switched and thus not detected. It should be noted that compared to other solutions that utilize atomic flags for each page and require maintaining all atomic flags at any startup, only two atomic flags are checked and conditionally enhanced at startup. In this case, scanning all atomic flags to determine which are weak and thus need to be enhanced takes more time at startup.

[0103] Once the TLE is identified, the strength of the TLE flag of the LTE is checked (606). If it is determined at decision diamond 608 that the TLE flag is weak, the TLE flag is enhanced (610) to make it reliable before proceeding. After the enhancement, or if the TLE flag is not determined to be weak, the strength of the TLE flag of the next (i.e., successor) entry is checked (612). If it is determined at decision diamond 614 that the TLE flag is weak, the TLE flag is enhanced (616). The TLE flags of successor entries are also checked and conditionally enhanced because a transaction may tear when switching the TLE flag of a successor entry, where the TLE flag may become weak but not fully switched and thus not detected. It should be noted that compared to other solutions that utilize atomic flags for each page and require maintaining all atomic flags at any startup, only two atomic flags are checked and conditionally enhanced at startup. In this case, scanning all atomic flags to determine which are weak and thus need to be enhanced takes more time at startup.

[0104] After the final strengthening of the two possibly weak flags, the descriptor of the LTE is read (618) to identify any abnormal pages. As described above, since the atomic TLE flag of the LTE is switched (and thus the discontinuity of the box 604 is detected), the corresponding descriptor information in the LTE of the GTL 18 is known to be secure and can be trusted as correct. Therefore, using the information of the descriptor, the mapping information (for example, obtained from the parameters P0 and P1, which identify the old physical address and the new physical address for the corresponding operation) can be obtained. The mapping information (for example, the physical page address and the mapping status) of any abnormal pages determined from the LTE of the GTL 18 (instead of being determined based on any MUF of the possibly unreliable physical pages) is stored (620) in a set of exception registers 22. For example, one register in the exception registers 22 can store the physical address of the mapped page, and another register in the exception registers 22 can store the physical address of the unmapped page (where the mapped page and the unmapped page can be determined from the descriptor of the LTE, as described in the example page transaction with reference to Figure 4 ). Additionally, in an embodiment where the logical address is also stored as part of the TLE descriptor of the transaction, the logical address of the mapped page can also be obtained from the descriptor of the LTE and stored in the exception registers 22. After the mapping information of the abnormal pages is stored, all pages of the NVM can be appropriately mapped (622) using the exception registers as needed.

[0105] It should be noted that, in addition to the physical address, other information can also be stored in the exception registers 22. For example, this information can be additional information obtained from the descriptor, such as the logical address or other additional information. Additionally, in an alternative embodiment, the exception registers can be extended to include additional exception registers for multiple page transactions. The set of exception registers 22 can include any number (i.e., one or more) of registers, can be any type of storage circuit system (for example, a volatile storage circuit system), and can be organized differently. They can also be located outside the NVM 14. Additionally, the strengthening of the atomic flag (at 610 and 616) can be performed at a later time but before the next transaction is executed.

[0106] Figure 7 A method 700 for performing a mapping operation using the exception registers 22 according to an embodiment of the present invention is shown in flowchart form. The mapping operation utilizes the current mapping of the physical pages in the NVM 14 to construct a mapping LUT 26, and then the system 10 (for example, the processor 12) can use the mapping LUT 26 to appropriately access the NVM 14. (This mapping operation can correspond to the operation in Figure 6The mapping performed at the frame 622. ) The mapping information used to construct the mapping LUT 26 is obtained by iteratively traversing all physical NVM pages and mapping the pages according to the metadata stored in the NVM 14. However, for the exception pages (stored in the exception register 22), the metadata is not trustworthy, so it is replaced by the data stored in the exception register 22. In this way, the obtained mapping information is trustworthy, and the pages can be mapped with the appropriate entries in the mapping LUT 26 (or skipped and possibly included in the free / unused page list).

[0107] Method 700 begins by setting a pointer to the first physical page address of the NVM 14 to select this first physical page as the current physical page to be processed (704). At decision diamond 706, it is determined whether the physical page address of the current physical page is one of the physical addresses stored in the exception register 22. If not, the MUF and the logical page address are read from the metadata of the current physical page (708). If so, instead, the mapping status (i.e., mapped or unmapped) is obtained from the exception register 22 (710). (In this case, the logical page address can be obtained from the exception register 22 (if stored there) or from the metadata of the current physical page, depending on the way the logical address update is handled during page transactions.) At decision diamond 712, it is determined whether the current physical page corresponds to a mapped page (as determined according to the MUF read from the current physical page or the mapping status read from the exception register). If so, the physical page address of the current physical page is written to the mapping LUT 26 at the index determined by the corresponding logical page address (which is read from the current physical page or from the exception register). If not, no update is performed on the mapping LUT 26, and if available, the page address of the current physical page can be added to the list of unmapped pages (716). Next, to iteratively process the next physical page, the pointer is incremented to select the next physical page address as the current physical page (718). If at decision diamond 720, the incremented pointer exceeds the page range (e.g., exceeds the last page of the NVM 14), the mapping operation is completed. If not, method 700 returns to decision diamond 706 to continue processing the next physical page (which now corresponds to the current physical page).

[0108] Thus, so far, it can be understood that using a global transaction log (with an atomic flag per entry) provides a mechanism to reliably distinguish old information and new information belonging to the same logical memory block. Even in the event of a tear event, the global transaction log and atomic flags can be properly restored at startup, where reliable mappings of all logical addresses are maintained. Each memory block (e.g., each page) may still include a non-atomic flag to indicate the mapping status of the page, but a tear event that renders the mapping status invalid or untrustworthy will not result in the loss of this information because it is backed up by the last valid entry (e.g., LTE) of the global transaction log. Additionally, using an atomic flag per GTL entry avoids the need for an atomic flag for each memory block or page. The global transaction log provides tear protection by allowing the effective identification of the LTE (e.g., the entry representing the last transaction that was confirmed but not yet terminated in the event of a tear event). Information from this LTE can then be used to obtain accurate mapping information for the affected pages without relying on any mapping flags (e.g., MUF) within the metadata of each potentially torn memory block or page. Furthermore, by limiting the number of atomic flags required, area, power, and time can be saved.

[0109] Each signal described herein can be designed as positive logic or negative logic, where negative logic can be indicated by a bar over the signal name or an asterisk (*) following the name. In the case of a negative logic signal, the signal is active low, where the logical true state corresponds to a logic level of zero. In the case of a positive logic signal, the signal is active high, where the logical true state corresponds to a logic level of one. It should be noted that any signal described herein can be designed as a negative logic signal or a positive logic signal. Thus, in alternative embodiments, those signals described as positive logic signals can be implemented as negative logic signals, and those signals described as negative logic signals can be implemented as positive logic signals.

[0110] Since the devices implementing the present invention are mostly composed of electronic components and circuits known to those skilled in the art, circuit details will not be explained to any greater extent than deemed necessary above in order to understand and appreciate the basic concepts of the present invention and in order not to obscure or deviate from the teachings of the present invention.

[0111] Where appropriate, some of the above embodiments can be implemented using a variety of different information processing systems. For example, although Figure 1And its discussion describes an exemplary information processing architecture, but presenting such an exemplary architecture is only for providing a useful reference when discussing various aspects of the present invention. Of course, the description of the architecture has been simplified for the purpose of the discussion, and the architecture is just one of many different types of suitable architectures that can be used according to the present invention. Those skilled in the art will recognize that the boundaries between the logic blocks are merely illustrative, and alternative embodiments may combine the logic blocks or circuit elements, or impose alternative decompositions of the functionality on various logic blocks or circuit elements. Therefore, it should be understood that the architecture depicted herein is merely exemplary, and in fact, many other architectures that implement the same functionality can be implemented.

[0112] In addition, for example, in one embodiment, the illustrated elements of system 10 are circuitry located on a single integrated circuit (e.g., SoC) or within the same device. Alternatively, system 10 may include any number of separate integrated circuits or separate devices interconnected with each other. For example, memory 14 may be located on the same integrated circuit as processor 12, or on a separate integrated circuit, or within another peripheral device or slave device that is discretely separated from the other elements of system 10.

[0113] In addition, those skilled in the art should recognize that the boundaries between the functionality of the operations described above are merely illustrative. The functionality of multiple operations can be combined into a single operation, and / or the functionality of a single operation can be distributed among additional operations. In addition, alternative embodiments may include multiple instances of a particular operation, and the order of the operations may be changed in various other embodiments.

[0114] Although the present invention has been described herein with reference to specific embodiments, various modifications and changes can be made without departing from the scope of the present invention as set forth in the appended claims. For example, the number of entries in the global transaction log may vary for different applications, such as based on the size of the memory and the durability required for each log entry. In addition, controller 20 (i.e., control circuitry 20) can be implemented with any type of circuitry or combination of circuitry, including logic circuitry, circuitry that executes software, etc. Therefore, the specification and drawings should be regarded as illustrative rather than having a limiting meaning, and all such modifications are intended to be included within the scope of the present invention. It is not intended that any of the advantages, merits, or solutions to problems described herein with respect to specific embodiments be construed as critical, essential, or indispensable features or elements of any or all of the claims.

[0115] As used herein, the term "coupled" is not intended to be limited to direct coupling or mechanical coupling.

[0116] Further, as used herein, the term "a" or "an" is defined as one or more than one. Further, the use of introductory phrases such as "at least one" and "one or more" in the claims should not be construed to imply that another claim element introduced by the indefinite article "a" or "an" limits any particular claim containing such introduced claim element to inventions containing only one such element, even when the same claim includes the introductory phrases "one or more" or "at least one" and an indefinite article such as "a" or "an". This also applies to the use of the definite article.

[0117] Unless stated otherwise, terms such as "first" and "second" are used arbitrarily to distinguish the elements so described. Thus, these terms are not necessarily intended to indicate a temporal or other precedence of such elements.

[0118] The following are various embodiments of the present invention. It should be noted that any of the following aspects can be used in combination with each other and with any of the disclosed embodiments arbitrarily.

[0119] In one embodiment, a non-volatile memory (NVM) system includes: a memory array partitioned into physical pages, each physical page configured to store a corresponding payload and corresponding metadata of the physical page; control circuitry; and a global transaction log (GTL) having a plurality of entries, wherein each entry is configured to store a transaction descriptor identifying a transaction and the corresponding physical page used by the transaction, and each entry has a corresponding transaction log entry (TLE) flag. The control circuitry is configured to fill the entries of the GTL in sequential order with each new transaction, and in response to completing storage of the transaction descriptor of the new transaction, program the corresponding TLE flag by toggling a logical state of the corresponding TLE flag. In one aspect, the transaction descriptor includes an opcode identifying a memory transaction type and a physical page address identifying a physical page. In another aspect, the memory transaction type includes a type selected from the group consisting of a page update transaction, a page allocation transaction, and a page release transaction. In yet another aspect, when the opcode of the transaction descriptor identifies the memory transaction type as a page update transaction, the transaction descriptor includes a first physical page address for identifying the physical page having old information and a second physical page address for identifying the physical page having new information. In another aspect of the embodiment, during startup of the memory system after a power loss, the control circuitry is configured to scan the GTL to find a discontinuity in the logical state of the TLE flags in order to identify a last transition entry (LTE) corresponding to the entry of the GTL that immediately precedes the discontinuity in sequential order. In another aspect, the TLE flag corresponding to the LTE has a different logical state from the successor entry of the GTL that immediately follows the discontinuity in sequential order. In yet another aspect, each TLE flag is implemented as an atomic flag, and the corresponding transaction descriptor of the LTE identifies the latest transaction, the corresponding transaction descriptor of which is confirmed to be reliably stored in the GTL before the power loss. In yet another aspect, during startup of the memory system, the control circuitry is further configured to, after identifying the LTE, identify any physical page used by the latest transaction as an exception page and store mapping information of the exception page into a set of exception registers. In yet another aspect, the corresponding metadata of each physical page is configured to store a logical address of the physical page and a non-atomic mapping flag for indicating whether the physical page is mapped to the logical address or unmapped. In yet another aspect, during startup of the memory system, the control circuitry is further configured to create a mapping table configured to store associated mapping information of each mapped physical page of the array by using the metadata corresponding to the mapped physical pages or a set of exception registers in order to obtain the associated mapping information.In yet another aspect, during startup of the memory system, the control circuitry is further configured to: create a mapping table by iteratively traversing each physical page address of the array, wherein for each physical page address, if the physical page address corresponds to an identified exception page, obtain a mapping status from a set of exception registers, otherwise obtain the mapping status from a non-atomic mapping flag of the corresponding metadata of the physical page address, wherein the mapping status indicates whether the physical page address is mapped or unmapped; and for each mapped physical page address, store mapping information of the physical page address into the mapping table. In another aspect, the control circuitry is further configured to: enhance a TLE flag corresponding to an LTE in response to determining that the TLE flag corresponding to the LTE is weakly programmed; and enhance a TLE flag corresponding to a successor entry in response to determining that the TLE flag corresponding to the successor entry is weakly programmed.

[0120] In another embodiment, a non-volatile memory (NVM) system includes: a memory array that is partitioned into physical pages, each physical page being configured to store a corresponding payload and corresponding metadata of the physical page; control circuitry; and a global transaction log (GTL) having a plurality of entries, where each entry is configured to store a transaction descriptor that identifies a page transaction and the physical page used by a page update transaction, each entry having a corresponding transaction log entry (TLE) flag, and each corresponding TLE flag being implemented as an atomic flag. In another embodiment, the control circuitry is configured to: fill the next entry of the GTL in sequential order with a new page transaction; after storing the transaction descriptor of the new page transaction into the next entry, confirm the new page transaction by toggling the logical state of the corresponding TLE flag; and terminate the new page transaction when the next page transaction after the new page transaction is received. In one aspect, the corresponding metadata of each physical page is configured to store the logical address of the physical page and a non-atomic mapping flag for indicating whether the physical page is mapped to the logical address or unmapped. In another aspect, during startup of the memory system after a power loss, the control circuitry is configured to scan the GTL to find a discontinuity in the logical state of the TLE flags in order to identify a last transition entry (LTE) corresponding to the entry immediately before the discontinuity in the GTL, and the transaction descriptor identification of the LTE is confirmed as the latest transaction that was in the GTL before the power loss but not yet terminated. In yet another aspect, during startup of the memory system, the control circuitry is further configured to, after identifying the LTE, identify any physical page used by the latest transaction as an exception page and store the mapping information of the exception page into a set of exception registers. In yet another aspect, during startup of the memory system, the control circuitry is further configured to: create a mapping table by iteratively traversing each physical page address of the array, where, for each physical page address, if the physical page address is identified as an exception page, obtain the mapping status from a set of exception registers, otherwise obtain the mapping status from the non-atomic mapping flag of the corresponding metadata of the physical page address, where the mapping status indicates whether the physical page address is a mapped page or an unmapped page; and for each mapped physical page address, store the mapping information of the physical page address into the mapping table. In yet another aspect, the control circuitry is further configured to: enhance the TLE flag corresponding to the LTE in response to determining that the TLE flag corresponding to the LTE is weakly programmed; and enhance the TLE flag corresponding to a subsequent entry in response to determining that the TLE flag corresponding to the subsequent entry is weakly programmed.In another aspect of another embodiment, when the transaction descriptor of a new page transaction identifies a page update transaction that updates the logical page mapping from an old physical page of a memory array to a new physical page of the memory array, the control circuitry is configured to terminate the new page transaction by: updating the non-atomic mapping flag of the corresponding metadata of the new physical page identified by the transaction descriptor of the new page transaction, and updating the non-atomic mapping flag of the corresponding metadata of the old physical page identified by the transaction descriptor of the old page transaction. In yet another aspect, the control circuitry is configured to roll back to the start entry of the GTL after each entry of the GTL has been filled.

Claims

1. A non-volatile memory (NVM) system, characterized in that: include: a memory array divided into physical pages, each physical page being configured to store a corresponding payload and corresponding metadata of the physical page; Control circuit system; as well as a global transaction log (GTL) having a plurality of entries, wherein each entry is configured to store a transaction descriptor identifying a transaction and a corresponding physical page used by the transaction, each entry having a corresponding transaction log entry (TLE) flag, wherein the control circuitry is configured to: populates the entries of the GTL in sequential order with each new transaction, and In response to completing storage of the transaction descriptor of the new transaction, the corresponding TLE flag is programmed by switching a logic state of the corresponding TLE flag.

2. The NVM system according to claim 1, characterized in that: The transaction descriptor includes an operation code identifying a memory transaction type and a physical page address identifying the physical page.

3. The NVM system according to claim 2, characterized in that: The memory transaction type comprises a type selected from the group consisting of a page update transaction, an allocate page transaction, and a release page transaction.

4. The NVM system according to claim 3, characterized in that: When the operation code of the transaction descriptor identifies the memory transaction type as the page update transaction, the transaction descriptor includes a first physical page address for identifying a physical page having old information and a second physical page address for identifying a physical page having new information.

5. The NVM system according to claim 1, characterized in that: During startup of the memory system after power loss, the control circuitry is configured to scan the GTL for a discontinuity in the logic state of the TLE flag to identify a last transition entry (LTE) corresponding to an entry of the GTL immediately preceding the discontinuity according to the sequential order.

6. The NVM system according to claim 5, characterized in that: The TLE flag corresponding to the LTE has a different logic state than a subsequent entry of the GTL that immediately follows the discontinuity according to the sequential order.

7. The NVM system according to claim 6, characterized in that: Each TLE flag is implemented as an atomic flag, and the corresponding transaction descriptor of the LTE identifies the latest transaction, and the corresponding transaction descriptor of the latest transaction is confirmed to be reliably stored in the GTL before the power loss.

8. The NVM system according to claim 7, characterized in that: During the startup of the memory system, the control circuitry is additionally configured to, after identifying the LTE: Identify any physical pages used by the most recent transaction as outlier pages, and The mapping information of the exception page is stored in a set of exception registers.

9. The NVM system according to claim 6, characterized in that: The control circuitry is additionally configured to: enhancing the TLE flag corresponding to the LTE in response to determining that the TLE flag corresponding to the LTE is weakly programmed; and The TLE flag corresponding to the successor entry is enhanced in response to determining that the TLE flag corresponding to the successor entry is weakly programmed.

10. A non-volatile memory (NVM) system, characterized in that: include: a memory array divided into physical pages, each physical page being configured to store a corresponding payload and corresponding metadata of the physical page; Control circuit system; as well as a global transaction log (GTL) having a plurality of entries, wherein each entry is configured to store a transaction descriptor identifying a page transaction and a physical page used by the page update transaction, each entry having a corresponding transaction log entry (TLE) flag, each corresponding TLE flag being implemented as an atomic flag, wherein the control circuitry is configured to: fill the next entry of the GTL with the new page transaction in sequential order, After completing storing the transaction descriptor of the new page transaction in the next entry, confirming the new page transaction by switching the logic state of the corresponding TLE flag, and When a next page transaction after the new page transaction is received, the new page transaction is terminated.

Citation Information

Patent Citations

  • Non-volative memory system configured to mitigate errors in read and write operations

    US20230315325A1