Memory device and method for refresh operation of the same

By introducing a row hammer management circuit into the DRAM memory device, monitoring and identifying the interference source rows and performing refresh operations on adjacent rows, the impact of the row hammer phenomenon on data is solved, and the reliability and stability of the memory device are improved.

CN120220753APending Publication Date: 2025-06-27SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410909096.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-27
Filing Date
2024-07-08
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Dynamic random access memory (DRAM) may cause row hammering during intensive access, affecting the charge of memory cells in adjacent rows, resulting in data corruption.

Method used

A refresh control circuit including a row hammer management circuit (RHMC) is designed, and the interference source row is monitored and identified through the first row address generator, the second row address generator and the row address inspector, and the corresponding refresh row address is generated, and a refresh operation is performed on adjacent rows.

Benefits of technology

Effectively monitor and manage row hammers to prevent data corruption and improve the reliability and stability of memory devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120220753A_ABST
    Figure CN120220753A_ABST
Patent Text Reader

Abstract

A memory device and a method for refresh operation of the memory device are provided. The memory device includes: a plurality of memory cells; and a refresh control circuit that generates a refresh row address and performs a refresh operation on the memory cells of the row corresponding to the refresh row address. The refresh control circuit includes a row hammer management circuit including: a first row address generator receiving first input row addresses during a first monitoring length and determining a first candidate address among the first input row addresses based on a first reference address; a second row address generator receiving second input row addresses during a second monitoring length longer than the first monitoring length and determining a second candidate address among the second input row addresses based on a second reference address; and a row address checker determining an interferer row address based on the first candidate address and the second candidate address.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a row hammer management circuit, a memory device including the row hammer management circuit, and a method for a refresh operation of the memory device. Background Art

[0002] A volatile memory device, such as a dynamic random access memory (DRAM), stores data by storing charges in a capacitor of a memory cell, and reads data by determining the charges stored in the capacitor. Since the charges stored in the capacitor may leak over time, the memory device needs to perform a refresh operation periodically.

[0003] A memory controller randomly accesses addresses of a memory device and typically accesses a specific address intensively. As the density of memory cells in the memory device increases, the voltage distribution of a specific row may affect the charges of memory cells in adjacent rows. Specifically, when a specific row is subjected to an intensive access attack, data stored in memory cells of an adjacent row may be changed due to the voltage in the activated state of the row. This phenomenon is referred to as row hammer. Therefore, it is desirable to monitor all rows of the memory device for row hammer care. Summary of the Invention

[0004] According to an embodiment, a memory device may include a memory cell array and a refresh control circuit. The memory cell array may include a plurality of memory cells. The refresh control circuit may generate a refresh row address and perform a refresh operation on memory cells of a row corresponding to the refresh row address. The refresh control circuit may include a row hammer management circuit (RHMC). The RHMC may include a first row address generator, a second row address generator, and a row address checker. The first row address generator may receive a first input row address during a first monitoring length and determine a first candidate address among the first input row addresses based on a first reference address. The second row address generator may receive a second input row address during a second monitoring length longer than the first monitoring length and determine a second candidate address among the second input row addresses based on a second reference address. The row address checker may determine an aggressor row address based on the first candidate address and the second candidate address. The row corresponding to the refresh row address may be adjacent to the row corresponding to the aggressor row address. Both the first monitoring length and the second monitoring length may be periods for performing the refresh operation.

[0005] According to an embodiment, a row hammer management circuit includes: a first row address generator that receives a first input row address during a first monitoring length and determines a first candidate address among the first input row addresses based on a first reference address; a second row address generator that receives a second input row address during a second monitoring length longer than the first monitoring length and determines a second candidate address among the second input row addresses based on a second reference address; and a row address checker that determines an interference source row address based on the first candidate address and the second candidate address.

[0006] According to an embodiment, a memory device may include a memory cell array and a refresh control circuit. The memory cell array may include a plurality of memory cells. The refresh control circuit may generate candidate addresses based on a reference address and row addresses input during different monitoring lengths, generate an interference source row address based on whether the candidate addresses match, and output a refresh row address of a row adjacent to the row corresponding to the interference source row address. The memory device may perform a refresh operation on the memory cells of the row corresponding to the refresh row address. The different monitoring lengths may each be a period for performing the refresh operation.

[0007] According to an embodiment, a method for a refresh operation of a memory device is provided. The method may include: receiving row addresses during different monitoring lengths; generating candidate addresses based on a reference address and the received row addresses; comparing the candidate addresses; modifying the reference address based on a comparison result; determining an interference source row address based on the comparison result; and performing a refresh on the memory cells of a row adjacent to the row corresponding to the interference source row address. The different monitoring lengths may each be a period for performing the refresh on the memory cells of the row adjacent to the row corresponding to the interference source row address. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 is a block diagram of a storage system according to an embodiment.

[0009] Figure 2 is a block diagram of a memory device according to an embodiment.

[0010] Figure 3 is a diagram showing the timing of a refresh operation of a memory device according to an embodiment.

[0011] Figure 4 is a block diagram of a row hammer management circuit according to an embodiment.

[0012] Figure 5 is a block diagram of a row hammer management circuit according to an embodiment.

[0013] Figure 6 It is a diagram for describing the timing of a refresh interval and an interference source pattern according to an embodiment.

[0014] Figure 7 It is a diagram for describing the interference source row refresh operation of a row hammer management circuit according to an embodiment.

[0015] Figure 8 It is a diagram for describing the timing of a refresh interval and an interference source pattern according to an embodiment.

[0016] Figure 9 It is a diagram for describing the interference source row refresh operation of a row hammer management circuit according to an embodiment.

[0017] Figure 10 It is a block diagram of a row hammer management circuit according to an embodiment.

[0018] Figure 11 It is a diagram for describing the timing of a refresh interval and an interference source pattern according to an embodiment.

[0019] Figure 12 It is a diagram for describing the interference source row refresh operation of a row hammer management circuit according to an embodiment.

[0020] Figure 13 It is a diagram for describing the timing of a refresh interval and an interference source pattern according to an embodiment.

[0021] Figure 14 It is a diagram for describing the interference source row refresh operation of a row hammer management circuit according to an embodiment.

[0022] Figure 15 It is a diagram for describing the timing of a refresh interval and an interference source pattern according to an embodiment.

[0023] Figure 16 It is a diagram for describing the interference source row refresh operation of a row hammer management circuit according to an embodiment.

[0024] Figure 17 It is a circuit diagram of a row hammer management circuit according to an embodiment.

[0025] Figure 18 It is a block diagram of a row address generator according to an embodiment.

[0026] Figure 19 It is a diagram for describing the timing of operations for managing row hammers according to an embodiment.

[0027] Figure 20 It is a flowchart of a method for generating an interference source row address according to an embodiment.

[0028] Figure 21is a block diagram of a computing system according to an embodiment.

[0029] Figure 22 is a diagram showing a memory module according to an embodiment.

[0030] Figure 23 is a diagram showing a semiconductor package according to an embodiment. Detailed Description

[0031] In the following detailed description, only certain exemplary embodiments of the present disclosure have been shown and described by way of illustration. As will be recognized by those skilled in the art, the described embodiments can be modified in various different ways, all of which do not depart from the spirit or scope of the present invention.

[0032] Accordingly, the drawings and description are to be regarded as illustrative in nature and not restrictive. Throughout the specification, the same reference numerals designate the same elements. In the flowcharts described with reference to the drawings, the order of operations can be changed, several operations can be combined, certain operations can be divided, and certain operations can be not performed.

[0033] In addition, unless an explicit statement such as "one" or "single" is used, a singular expression can be interpreted as singular or plural. Terms including ordinal numbers such as first and second can be used to describe various components, but the components are not limited by these terms. These terms can be used to distinguish one component from another.

[0034] Figure 1 is a block diagram of a storage system according to an embodiment.

[0035] Reference Figure 1 , a storage system 100 according to an embodiment can include a memory device 110 and a memory controller 120. In some embodiments, the memory device 110 and the memory controller 120 are connected through a memory interface and can exchange signals through the memory interface.

[0036] The memory device 110 may include a memory cell array 111 and a refresh control circuit 112. The memory cell array 111 may include a plurality of memory cells defined by a plurality of rows and a plurality of columns. In some embodiments, the rows may be defined by word lines and the columns may be defined by bit lines. The refresh control circuit 112 detects a disturbed source row (or attacked row) among the plurality of rows, determines a row address of a sacrificial row to be refreshed (the "sacrificial row address") based on the row address of the disturbed source row (referred to as the "disturbed source row address"), and outputs the sacrificial row address. In some embodiments, the disturbed source row may be a row hammer disturbed source row, and the sacrificial row may be a row targeted as row hammer care. In some embodiments, the refresh control circuit 112 may select the disturbed source row address at a refresh time and output the sacrificial row address.

[0037] The memory controller 120 provides signals to the memory device 110 to control the memory operations of the memory device 110. The signals may include a command CMD and an address ADDR. In some embodiments, the memory controller 120 may further provide a clock signal to the memory device 110 and provide the command CMD and the address ADDR to the memory device 110 in synchronization with the clock signal, thereby controlling the operations of the memory device 110.

[0038] In some embodiments, the memory controller 120 may provide the command CMD and the address ADDR to the memory device 110 to access the memory cell array 111 and control memory operations such as reading or writing. According to the read operation, data may be sent from the memory cell array 111 to the memory controller 120, while according to the write operation, data may be sent from the memory controller 120 to the memory cell array 111.

[0039] The command CMD may include an activation command, a read / write command, and a refresh command. In some embodiments, the command CMD may further include a precharge command. The activation command may be a command to switch a target row of the memory cell array 111 to an active state to write data to the memory cell array 111 or read data from the memory cell array 111. The memory cells of the target row may be activated (e.g., driven) in response to the activation command. The read / write command may be a command to perform a read operation or a write operation on the target memory cells of the row that has been switched to the active state. The refresh command may be a command to perform a refresh operation in the memory cell array 111.

[0040] The memory device 110 may generate a disturbed source row refresh command signal in response to the refresh command. The disturbed source row refresh may refer to an operation of detecting a disturbed source pattern having a consistent row distribution type and sequentially refreshing the sacrificial rows (adjacent rows) of the disturbed source rows determined from the disturbed source pattern.

[0041] The refresh control circuit 112 may determine a source row of interference in response to a source row refresh command signal and output a source row address. In an embodiment, the length (or size) of a source pattern of interference (or intrusion) that interferes with the memory cells of the memory device 110 may be different. The refresh control circuit 112 may include a plurality of row address generators and a row address checker to protect against various source patterns of various lengths. The plurality of row address generators determine the source row of interference, and the row address checker may verify the source row of interference determined by the plurality of row address generators. The lengths of the source patterns monitored by the plurality of row address generators may be different. The configurations of the plurality of row address generators and the row address checker will be described later with reference to Figures 4 to 19 the configurations of the plurality of row address generators and the row address checker.

[0042] In some embodiments, the memory device 110 may generate a normal refresh command signal or a target row refresh (TRR) command signal in response to a refresh command. The memory device 110 may include a command decoder (or control logic) that generates a command signal in response to a refresh command. The TRR command signal may be a refresh command that determines a sacrificial row based on the counted number of activation commands and indicates an operation to refresh the sacrificial row. The normal refresh command signal may be a refresh command that indicates a normal refresh operation (e.g., an operation of sequentially refreshing the rows of the memory cell array 111).

[0043] In some embodiments, the source row refresh command signal may be included in the TRR command signal. For example, the memory device 110 may generate some TRR command signals as source row refresh command signals based on a predetermined ratio. The memory cell array 111 may be refreshed in response to a refresh command.

[0044] In some embodiments, based on a request from a host external to the storage system 100, the memory controller 120 may access the memory device 110. The memory controller 120 may communicate with the host using various protocols.

[0045] The memory device 110 may be a semiconductor device-based storage device. In some embodiments, the memory device 110 may include a dynamic random access memory (DRAM) device. Examples of the memory device 110 may include a double data rate synchronous dynamic random access memory (DDR SDRAM), a low power double data rate (LPDDR) SDRAM, a graphics double data rate (GDDR) SDRAM, and a rambus dynamic random access memory (RDRAM), etc.

[0046] In some embodiments, the memory device 110 may include other volatile or non-volatile memory devices in which a refresh operation is used.

[0047] Figure 2 is a block diagram of a memory device 200 according to an embodiment. Figure 3 is a diagram showing the timing of a refresh operation of the memory device 200 according to an embodiment.

[0048] Reference Figure 2 , the memory device 200 according to an embodiment may include a memory cell array 210, sense amplifiers 211, a command decoder 220, an address buffer 230, bank control logic 240, a row decoder 250, a row address multiplexer (RAMUX) 251, a column decoder 260, an input / output (I / O) gating circuit 270, a data I / O buffer 280, and a refresh control circuit 290. The memory device 200, the memory cell array 210, and the refresh control circuit 290 may respectively correspond to Figure 1 the memory device 110, the memory cell array 111, and the refresh control circuit 112 of

[0049] The memory cell array 210 may include a plurality of memory cells MC. In some embodiments, the memory cell array 210 may include a plurality of memory banks 210a to 210h. Although eight memory banks (e.g., BANK0 210a to BANK7 210h) are shown in Figure 2 , the number of memory banks is not limited thereto. Each of the memory banks 210a to 210h may include a plurality of rows, a plurality of columns, and a plurality of memory cells MC arranged at the intersections of the plurality of rows and the plurality of columns. In some embodiments, the plurality of rows may be defined by a plurality of word lines WL, and the plurality of columns may be defined by a plurality of bit lines BL.

[0050] The command decoder 220 may generate control signals to enable the memory device 200 to perform read operations, write operations, or refresh operations. The command decoder 220 may generate internal command signals ICS by decoding a command CMD received from a memory controller ( Figure 1 120 in

[0051] Reference Figure 2 and Figure 3, a 32 ms or 64 ms refresh window time tREFw defined in the Joint Electron Device Engineering Council (JEDEC) standard can be set. The memory controller 120 can send a refresh command REFRESH to cause the memory device 200 to complete a refresh during the refresh window time tREFw. For example, the memory controller 120 can send a refresh command REFRESH based on a base refresh rate time tREFi. The base refresh rate time tREFi can be defined as, for example, the number of refresh commands REFRESH of approximately 8K within a 32 ms refresh window time tREFw. However, it is not limited thereto.

[0052] In some embodiments, based on receiving the refresh command REFRESH, the memory device 200 can generate a victim row refresh command signal, a normal refresh command signal, a TRR command signal, etc. The memory device 200 can nurse a victim row through a victim row during the refresh window time tREFw based on the victim row refresh command signal.

[0053] Return reference Figure 2 , the address buffer 230 can receive an address ADDR provided from the memory controller 120. The address ADDR can include a row address RA indicating a row of the memory cell array 210 and a column address CA indicating a column. The row address RA is provided to the row decoder 250, and the column address CA is provided to the column decoder 260. The row address RA can be provided to the refresh control circuit 290 through the command decoder 220 or directly provided to the refresh control circuit 290. In some embodiments, the row address RA can be provided to the row decoder 250 through a row address multiplexer 251. In some embodiments, the address ADDR can further include a bank address BA indicating a memory bank.

[0054] In some embodiments, the row address multiplexer 251 can receive a row address RA from the address buffer 230 and a row address REF_RA to be refreshed from the refresh control circuit 290. The row address multiplexer 251 can selectively output the row address RA received from the address buffer 230 and the row address REF_RA received from the refresh control circuit 290 to the row decoder 250. In some embodiments, the row address multiplexer 251 can receive an internal command signal ICS (e.g., a refresh signal) of the command decoder 220. The row address multiplexer 251 can output the row address REF_RA to be refreshed in response to the internal command signal ICS.

[0055] In Figure 2 , the command decoder 220 and the address buffer 230 are shown as separate components, but are not necessarily limited thereto, and the command decoder 220 and the address buffer 230 can be implemented as an inseparable component.

[0056] The row decoder 250 may select a row to be activated among multiple rows of the memory cell array 210 based on the row address RA or REF_RA. To this end, the row decoder 250 may apply a driving voltage to the row to be activated. In some embodiments, multiple row decoders 250a to 250h corresponding to the multiple memory banks 210a to 210h may be provided, respectively.

[0057] The column decoder 260 may select a column to be activated among multiple columns of the memory cell array 210 based on the column address CA. To this end, the column decoder 260 may activate the sense amplifier 211 corresponding to the column address CA through the I / O strobe circuit 270. In some embodiments, multiple column decoders 260a to 260h corresponding to the multiple memory banks 210a to 210h may be provided, respectively. In some embodiments, the I / O strobe circuit 270 strobes input / output data and may include a data latch for storing data read from the memory cell array 210 and a write driver for writing data to the memory cell array 210. The data read from the memory cell array 210 may be detected by the sense amplifier 211 and stored in the I / O strobe circuit 270 (e.g., the data latch). In some embodiments, multiple sense amplifiers 211a to 211h corresponding to the multiple memory banks 210a to 210h may be provided, respectively.

[0058] In some embodiments, the bank control logic 240 may generate bank control signals in response to the bank address BA. In response to the bank control signals, the row decoder 250 corresponding to the bank address may be activated (e.g., among the multiple row decoders 250a to 250h), and the column decoder 260 corresponding to the bank address may be activated (e.g., among the multiple column decoders 260a to 260h). The activated row decoder may apply a driving voltage to the row to be activated.

[0059] In some embodiments, the data read from the memory cell array 210 (e.g., the data stored in the data latch) may be provided to the memory controller 120 through the data I / O buffer 280. The data to be written to the memory cell array 210 may be provided from the memory controller 120 to the data I / O buffer 280, and the data provided to the data I / O buffer 280 may be provided to the I / O strobe circuit 270.

[0060] Refer together Figure 1, the memory controller 120 may periodically send refresh-related commands CMD to the memory device 110. The refresh control circuit 290 may schedule the refresh based on the command CMD. Scheduling the refresh by the refresh control circuit 290 may be understood as determining the ratio between normal refresh and TRR and periodically generating a normal refresh command signal and a TRR command signal based on the determined ratio. Additionally, the refresh control circuit 290 may generate some TRR command signals as disturbance source row refresh command signals based on a predetermined ratio.

[0061] The refresh control circuit 290 may send the row address REF_RA to be refreshed to the row decoder 250 in response to the refresh signal among the internal command signals ICS. The refresh control circuit 290 may include a row hammer management circuit (RHMC) 291. The row hammer management circuit 291 may monitor the disturbance source pattern and determine the disturbance source row from the disturbance source pattern. The row hammer management circuit 291 may sequentially output the addresses of the disturbance source rows in response to the disturbance source row refresh command signals. For example, the row hammer management circuit 291 may output the first disturbance source row address in response to the first disturbance source row refresh command signal, and output the second disturbance source row address in response to the second disturbance source row refresh command signal. The address value of the second disturbance source row address may be greater than the address value of the first disturbance source row address, but the embodiment is not necessarily limited thereto.

[0062] The row hammer management circuit 291 may include a plurality of row address generators and row address checkers to protect against disturbance source patterns of various lengths. The monitoring lengths (or intervals) of the plurality of row address generators may be different. For example, the plurality of row address generators may include a first row address generator and a second row address generator. The first row address generator may generate row addresses based on a first monitoring length, and the second row address generator may generate row addresses based on a second monitoring length longer than the first monitoring length. The row address checker may determine one of the row addresses received from the plurality of row address generators as the disturbance source row address. The configuration of the plurality of row address generators and the row address checker will be described later with reference to Figures 4 to 19 Describe the configuration of the plurality of row address generators and the row address checker.

[0063] In some embodiments, the row hammer management circuit 291 may be included in the memory controller 120.

[0064] The refresh control circuit 290 may determine the sacrifice row address based on the disturbance source row address. The refresh control circuit 290 may output the sacrifice row address as the row address REF_RA to be refreshed.

[0065] In some embodiments, the refresh control circuit 290 may further include a TRR control circuit and a normal refresh control circuit. The TRR control circuit may determine an interference source row based on the counted number of activation commands, and determine a sacrifice row address based on the determined interference source row. The TRR control circuit may output a row address for which TRR will be performed in response to a TRR command signal among the internal command signals ICS.

[0066] The normal refresh control circuit may output a row address for which a normal refresh operation will be performed in response to a normal refresh command signal among the internal command signals ICS. Whenever a normal refresh operation is performed, the normal refresh control circuit may sequentially increment or decrement the row address.

[0067] In some embodiments, the refresh control circuit 290 may further include a refresh row address selector. The refresh row address selector may selectively output a row address determined by the row hammering management circuit 291, the TRR control circuit, and the normal refresh control circuit. For example, the refresh row address selector may output one of the row addresses as a refresh row address REF_RA in response to a refresh signal.

[0068] Figure 4 is a block diagram of a row hammering management circuit 300 according to an embodiment. The row hammering management circuit 300 may correspond to Figure 2 the row hammering management circuit 291.

[0069] Refer to Figure 4 , the row hammering management circuit 300 according to an embodiment may generate an interference source row address AGRA. The row hammering management circuit 300 may monitor the row address input together with the activation command and detect an interference source pattern from the row address. The row hammering management circuit 300 may sequentially output the interference source row address AGRA based on the interference source row of the interference source pattern.

[0070] The row hammering management circuit 300 according to an embodiment may include a plurality of row address generators 310, 320, and 330 and a row address checker (REFA checker) 350.

[0071] Multiple row address generators 310, 320, and 330 may receive an activation command and a row address. The multiple row address generators 310, 320, and 330 may have different monitoring lengths. For example, the multiple row address generators 310, 320, and 330 may include a first row address generator RGEN1 310 operating based on a first monitoring length, second row address generators RGEN2_1 and RGEN2_2 320 operating based on a second monitoring length, and a Kth row address generators RGENK_1 to RGENK_M 330 (K is an integer greater than 2) operating based on a Kth monitoring length. In this case, the second monitoring length may be longer than the first monitoring length, and the Kth monitoring length may be longer than the second monitoring length.

[0072] In an embodiment, the Figure 2 command decoder 220 or the refresh control circuit 290 in the memory device 200 may send a disturbance source row refresh command signal based on the monitoring lengths of the multiple row address generators 310, 320, and 330. For example, the command decoder 220 or the refresh control circuit 290 may use the first monitoring length to send a disturbance source row refresh command signal to the first row address generator 310. The command decoder 220 or the refresh control circuit 290 may use the first monitoring length as a period for sending the disturbance source row refresh command signal. Similarly, the command decoder 220 or the refresh control circuit 290 may use the second monitoring length and the Kth monitoring length to send a disturbance source row refresh command signal to each of the second row address generator 320 and the Kth row address generator 330.

[0073] Each of the second row address generator 320 and the Kth row address generator 330 may also include multiple row address generators. The number of row address generators included in the second row address generator 320 and the Kth row address generator 330 may be determined based on the monitoring length. For example, the row hammer management circuit 300 may include 2 N-1 Nth row address generators having an Nth monitoring length that is N times (N is an integer greater than 1) the first monitoring length.

[0074] In an embodiment, the second row address generator 320 may include two second row address generators 321 and 322. The second monitoring length of the second row address generator 320 may be twice the first monitoring length. The monitoring start times of the second row address generators 321 and 322 may be different.

[0075] In an embodiment, the Kth row address generator 330 may include M Kth row address generators 331 to 333. The Kth monitoring length of the Kth row address generator 330 may be K times the first monitoring length. At this time, M may be equal to 2 K-1。The monitoring start times of the K-th row address generators 331 to 333 may be different.

[0076] Multiple row address generators 310, 320, and 330 may monitor row addresses based on their own monitoring lengths. Multiple row address generators 310, 320, and 330 may determine candidate addresses from the row addresses. Multiple row address generators 310, 320, and 330 may output the candidate addresses to the row address checker 350 when receiving an interference source row refresh command signal. In an exemplary embodiment, the time when the command decoder 220 or the refresh control circuit 290 sends an interference source row refresh command signal to the multiple row address generators 310, 320, and 330 may be the same or different.

[0077] The row address checker 350 may generate an interference source row address AGRA based on the candidate addresses received from the multiple row address generators 310, 320, and 330.

[0078] The row address checker 350 may verify the multiple row address generators 310, 320, and 330 based on the candidate addresses. For example, if the candidate addresses match, the row address checker 350 may determine that the multiple row address generators 310, 320, and 330 are working properly. When the candidate addresses do not match, the row address checker 350 may determine that at least one of the multiple row address generators 310, 320, and 330 is working abnormally.

[0079] In an embodiment, the row address checker 350 may compare the candidate addresses of row address generators at adjacent levels. Row address generators at adjacent levels may refer to row address generators having adjacent monitoring lengths. For example, the first row address generator 310 and the second row address generator 320 may be row address generators at adjacent levels.

[0080] The row address checker 350 may compare the candidate address of the first row address generator 310 with the candidate address of the second row address generator 320. For example, the row address checker 350 may compare the candidate addresses of the first row address generator 310 and the second row address generator 321 at the first interference source row refresh time. Also, for example, the row address checker 350 may compare the candidate addresses of the first row address generator 310 and the second row address generator 322 at the first interference source row refresh time and the subsequent second interference source row refresh time.

[0081] The row address checker 350 may compare the candidate addresses at different times. For example, at the second interference source row refresh time, the row address checker 350 may compare the candidate address of the first row address generator 310 at the first interference source row refresh time with the candidate address of the second row address generator 321 at the second interference source row refresh time. This will be referred to later Figures 4 to 17Describe the configuration of the row address checker 350 that compares candidate addresses.

[0082] In an embodiment, when the candidate addresses of the first row address generator 310 and the second row address generator 320 do not match, the row address checker 350 may determine that the first row address generator 310 is operating abnormally. That is, when the candidate addresses of the row address generators at adjacent levels do not match, the row address checker 350 may determine that the row address generator at the previous level among the two levels is operating abnormally. For example, among the first level and the second level, the first level may be the level before the second level.

[0083] The row address checker 350 may correct the reference address of the first row address generator 310 that is operating abnormally. The first row address generator 310 may generate a candidate address based on the corrected reference address.

[0084] Similarly, the row address checker 350 may compare the candidate addresses of the Kth row address generator 330 and the row address generator at the previous level, and determine the row address generator that is operating abnormally. In an embodiment, when K is 3, the row address generator at the previous level of the Kth row address generator 330 may be the second row address generator 320.

[0085] In addition, the row address checker 350 may determine one of the candidate addresses as the interference source row address AGRA based on the comparison result. The row address checker 350 may output the interference source row address AGRA. For example, when the multiple row address generators 310, 320, and 330 are operating normally, the row address checker 350 may determine the candidate address of the earliest-level row address generator (i.e., the first row address generator 310) as the interference source row address AGRA.

[0086] When at least one of the multiple row address generators 310, 320, and 330 is operating abnormally, the row address checker 350 may determine the candidate address of the row address generator at the subsequent level of the abnormally operating row address generator as the interference source row address AGRA. For example, the row address checker 350 may determine the candidate address of the second row address generator 320 as the interference source row address AGRA when the first row address generator 310 is abnormal, and determine the candidate address of the Kth row address generator 330 as the interference source row address AGRA when the second row address generator 320 is abnormal (when K is 3).

[0087] The row address checker 350 may correct the reference address of the abnormally operating generator. The multiple row address generators 310, 320, and 330 may generate candidate addresses by comparing the reference address and the row address.

[0088] Figure 5 Is a block diagram of a row hammer management circuit 400 according to an embodiment.Figure 6 This is a diagram for describing the timing of a refresh interval and an interference source pattern according to an embodiment. Figure 7 This is a diagram for describing the interference source row refresh operation of a row hammer management circuit according to an embodiment.

[0089] Reference Figure 5 , according to an embodiment, the row hammer management circuit 400 may include a first row address generator 410, a second row address generator 420, and a row address checker 450. Descriptions of the first row address generator 410 and the second row address generator 420 may equally apply to those of Figure 4 the first row address generator 310 and the second row address generator 320. Therefore, overlapping descriptions will be omitted.

[0090] The row address checker 450 may receive candidate addresses from the first row address generator 410 and the second row address generator 420. The row address checker 450 may generate an interference source row address AGRA based on the candidate addresses. In an embodiment, the row address checker 450 may output one of the candidate addresses as the interference source row address AGRA.

[0091] Reference Figure 5 and Figure 6 , according to an embodiment, the row address checker 450 may perform an interference source row refresh operation at a refresh interval. For example, the row address checker 450 may perform an interference source row refresh operation at times t1, t5, and t8. In some embodiments, a normal refresh operation or a TRR operation may be performed between times t1, t5, and t8. In some embodiments, the refresh interval may be Figure 3 an integer multiple of the basic refresh rate time tREFi of Figure 3 . The refresh shown in Figure 6 may be an interference source row refresh, a normal refresh, or a TRR, and the refresh shown in

[0092] The row address checker 450 may receive an interference source pattern from time t2 to t4. The interference source pattern may have a consistent row distribution type. In other words, the interference source pattern may be a pattern that repeatedly activates a specific number of rows. In an embodiment, the interference source pattern may be shorter than (or shorter than or equal to) the "refresh interval". The row address checker 450 may sequentially process the interference source rows of the interference source pattern at times t5 and t8. For example, the interference source pattern may include a first interference source row and a second interference source row. The second interference source row may have a larger row address number than the first interference source row. The row address checker 450 may refresh the adjacent row of the first interference source row at time t5. The row address checker 450 may refresh the adjacent row of the second interference source row at time t8.

[0093] ReferenceFigures 5 to 7 , the row hammer management circuit 400 according to an embodiment may perform aggressor row refresh operations F0 to F5 from time tf0 to tf5.

[0094] The first row address generator 410 and the second row address generator 420 may send candidate addresses B to F to the row address checker 450 at times tf0 to tf5. In an embodiment, Figure 7 The times tf0, tf1 and tf2 in can correspond to Figure 6 The times t1, t5 and t8 in FIG.

[0095] The first row address generator 410 may send a candidate address based on a first monitoring length. The first monitoring length may correspond to “ Figure 6 The first row address generator 410 may be initialized at time tf0 and may start operating upon receiving the reference address A. The first row address generator 410 may receive the reference address A from the row address checker 450. In an embodiment, the reference address A may be a first input row address.

[0096] The first row address generator 410 may output a candidate address B at time tf1 based on the row address received from time tf0 to time tf1 and the reference address A. At time tf1, the second row address generator 420 does not output a candidate address, and the row address checker 450 may output the candidate address B as the aggressor row address AGRA. Figure 18 and Figure 19 A configuration in which the first row address generator 410 determines a candidate address based on a row address and a reference address is described.

[0097] The second row address generator 420 may send a candidate address based on the second monitoring length. The second monitoring length may correspond to “( Figure 6 The refresh interval in ()×2". The time tf0 at which the second row address generator 421 starts monitoring may be different from the time tf1 at which the second row address generator 422 starts monitoring. For example, the second row address generator 420 may send candidate addresses alternately. For example, the second row address generator 421 may send candidate addresses B and D at times tf2 and tf4, and the second row address generator 422 may send candidate addresses C and E at times tf3 and tf5.

[0098] The row address checker 450 may compare the previous candidate address B of the first row address generator 410 with the candidate address B of the second row address generator 421 at time tf2 (S11). The candidate address B of the first row address generator 410 as a comparison target may be the candidate address B output at the previous time tf1. For example, the row address checker 450 may store the candidate address output from the first row address generator 410.

[0099] The row address checker 450 may confirm that the candidate address B matches and determine that the row address generators 410 and 421 are operating properly. The row address checker 450 may output the candidate address C of the first row address generator 410 as the disturbance source row address AGRA.

[0100] The row address checker 450 may send a reference address change signal to the second row address generator 421. The reference address change signal may include the candidate address C of the first row address generator 410 at time tf2. The second row address generator 421 may change the reference address to C based on the reference address change signal. The second row address generator 421 may output a candidate address D at time tf4 based on the row addresses received from time tf2 to time tf4 and the reference address C.

[0101] Similarly, the row address checker 450 may compare the previous candidate address C of the first row address generator 410 with the candidate address C of the second row address generator 421 at time tf3 (S12). Since the candidate addresses C match, the row address checker 450 may output the candidate address D as the disturbance source row address AGRA. The row address checker 450 may change the reference address of the second row address generator 422 to D.

[0102] The row address checker 450 may perform comparison operations at times tf4 and tf5 (S13 and S14) and output the candidate addresses E and F as the disturbance source row address AGRA. In this way, the row hammer management circuit 400 can be protected from disturbance source patterns shorter than the refresh interval.

[0103] Figure 8 is a diagram for describing the timing of the refresh interval and the disturbance source pattern according to an embodiment. Figure 9 is a diagram for describing the disturbance source row refresh operation of the row hammer management circuit according to an embodiment.

[0104] Reference Figure 5 and Figure 8 , the row address checker 450 according to an embodiment may perform a disturbance source row refresh operation at the refresh interval. For example, the row address checker 450 may perform a disturbance source row refresh operation at times t1, t5, and t8. In some embodiments, a normal refresh operation or a TRR operation may be performed between times t1, t5, and t8. In some embodiments, the refresh interval may be Figure 3 an integer multiple of the base refresh rate time tREFi.

[0105] The row address checker 450 may receive a disturbance source pattern at times t2 to t7. The disturbance source pattern may have a consistent row distribution type. In other words, the disturbance source pattern may be a pattern that repeatedly activates a specific number of rows. In an embodiment, the disturbance source pattern may be longer than the "refresh interval" and shorter than (or shorter than or equal to) "refresh interval × 2". The row address checker 450 may process the disturbance source rows of the disturbance source pattern at time t8.

[0106] Reference Figure 5 、 Figure 8 and Figure 9 , according to an embodiment, the row hammer management circuit 400 may perform disturbance source row refresh operations F0 to F4 at times tf0 to tf4.

[0107] The first row address generator 410 and the second row address generator 420 may send candidate addresses B to F to the row address checker 450 at times tf0 to tf4. In an embodiment, Figure 9 times tf2, tf3, and tf4 in Figure 8 may correspond to times t1, t5, and t8 in

[0108] The operations of the row hammer management circuit 400 from time tf0 to tf2 may be the same as those in Figure 7 and Figure 9 . That is, comparison operation S11 and comparison operation S21 may be the same, and overlapping descriptions will be omitted.

[0109] Since the disturbance source pattern is longer than the refresh interval, the first row address generator 410 that determines candidate addresses based on the refresh interval may determine incorrect candidate addresses. For example, the first row address generator 410 may output candidate address E at time tf3 based on the row address received from time tf2 to time tf3 and reference address C. At time tf3, candidate address E is not a comparison target, so it may not be possible to determine whether candidate address E is incorrect.

[0110] The row address checker 450 may compare the previous candidate address C of the first row address generator 410 with the candidate address C of the second row address generator 422 at time tf3 (S22). The candidate address C of the first row address generator 410 as the comparison target may be the candidate address C output at the previous time tf2.

[0111] The row address checker 450 may confirm that the candidate addresses C match and determine that the row address generators 410 and 422 are working properly. The row address checker 450 may output the candidate address E of the first row address generator 410 as the disturbance source row address AGRA.

[0112] The row address checker 450 may send a reference address change signal to the second row address generator 422. The reference address change signal may include the candidate address E of the first row address generator 410 at time tf3. The second row address generator 422 may change the reference address to E based on the reference address change signal.

[0113] The second row address generator 421 may output a candidate address D at time tf4 based on the row addresses received from time tf2 to time tf4 and the reference address C.

[0114] The row address checker 450 may compare the previous candidate address E of the first row address generator 410 with the candidate address D of the second row address generator 421 at time tf4 (S23). Since the candidate addresses D and E do not match, the row address checker 450 may determine that the first row address generator 410 of the previous stage (stage 1) is operating abnormally. That is, when the candidate addresses do not match, the row address checker 450 may determine that the row address generator of the previous stage is abnormal. In Figure 9 the embodiment, the interference source pattern is longer than the "refresh interval" and shorter than (or shorter than or equal to) "refresh interval × 2", so the second row address generator 420 may normally output a candidate address.

[0115] The row address checker 450 may change the reference address of the first row address generator 410 to the candidate address D of the second row address generator 421. That is, the first row address generator 410 outputs a candidate address F at time tf4, but since the candidate address F is generated based on the incorrect candidate address E at time tf3, the reference address is changed to D.

[0116] The row address checker 450 may initialize the second row address generator 422. In this case, initialization may mean deactivating the candidate address. For example, the row address checker 450 may deactivate the candidate address to be output by the second row address generator 422 at a time after time tf4 (e.g., tf5). In other words, the row address checker 450 may not use the candidate address output from the second row address generator 422 in the comparison operation at time tf5. The second row address generator 422 may output a candidate address based on the reference address C at the subsequent refresh time of the interference source row refresh operation F4.

[0117] Because the row address checker 450 determines that the first row address generator 410 is abnormal in the comparison operation (S23), it may output the candidate address D of the second row address generator 421 as the interference source row address AGRA. In this way, the row hammer management circuit 400 can be protected from the interference source pattern longer than the refresh interval.

[0118] Figure 10It is a block diagram of a row hammer management circuit according to an embodiment. Figure 11 It is a diagram for describing the timing of a refresh interval and a disturbance source pattern according to an embodiment. Figure 12 It is a diagram for describing the disturbance source row refresh operation of a row hammer management circuit according to an embodiment.

[0119] Reference Figure 10 , the row hammer management circuit 500 according to an embodiment may include a first row address generator 510, a second row address generator 520, a third row address generator 530, and a row address checker 550. Descriptions of the first row address generator 510 and the second row address generator 520 may equally apply to the descriptions of Figure 5 the first row address generator 410 and the second row address generator 420. Therefore, overlapping descriptions will be omitted.

[0120] The third row address generator 530 may include four third row address generators 531 to 534. The third monitoring length of the third row address generator 530 may be four times the first monitoring length. The third row address generators 531 to 534 may have different monitoring start times. The third row address generators 531 to 534 may start monitoring at intervals of the first monitoring length. For example, the third row address generator 531 may start monitoring, and the third row address generator 532 may start monitoring after the first monitoring length.

[0121] The row address checker 550 may receive candidate addresses from the first row address generator 510 to the third row address generator 530. The row address checker 550 may generate a disturbance source row address AGRA based on the candidate addresses. In an embodiment, the row address checker 550 may output one of the candidate addresses as the disturbance source row address AGRA.

[0122] Reference Figure 10 and 11 , the row address checker 550 according to an embodiment may perform a disturbance source row refresh operation at a refresh interval. For example, the row address checker 550 may perform a disturbance source row refresh operation at times t1, t5, t8, t11, and t14. In some embodiments, a normal refresh operation or a TRR operation may be performed between times t1, t5, t8, t11, and t14. In some embodiments, the refresh interval may be Figure 3 an integer multiple of the basic refresh rate time tREFi of

[0123] The row address checker 550 may receive a disturbance source pattern from time t2 to t4. The disturbance source pattern may have a consistent row distribution type. In other words, the disturbance source pattern may be a pattern that repeatedly activates a specific number of rows. In an embodiment, the disturbance source pattern may be shorter than (or shorter than or equal to) the "refresh interval". The row address checker 550 may sequentially process the disturbance source rows of the disturbance source pattern at times t5, t8, t11, and t14. For example, the disturbance source pattern may include a first disturbance source row, a second disturbance source row, a third disturbance source row, and a fourth disturbance source row. The second disturbance source row may have a row address number greater than that of the first disturbance source row, the third disturbance source row may have a row address number greater than that of the second disturbance source row, and the fourth disturbance source row may have a row address number greater than that of the third disturbance source row. The row address checker 550 may sequentially refresh the adjacent rows of the first to fourth disturbance source rows at times t5, t8, t11, and t14.

[0124] Reference Figures 10 to 12 , the row hammer management circuit 500 according to an embodiment may perform disturbance source row refresh operations F0 to F7 at times tf0 to tf7.

[0125] The first row address generator 510 to the third row address generator 530 may send candidate addresses B to H to the row address checker 550 at times tf0 to tf7. In an embodiment, Figure 12 times tf0, tf1, tf2, tf3, and tf4 may correspond to Figure 11 times t1, t5, t8, t11, and t14.

[0126] The first row address generator 510 may send a candidate address based on a first monitoring length. The first monitoring length may correspond to the " Figure 11 refresh interval in ". The second row address generator 520 may send a candidate address based on a second monitoring length. The second monitoring length may correspond to "(( Figure 11 refresh interval in )×2)". The third row address generator 530 may send a candidate address based on a third monitoring length. The third monitoring length may correspond to "(( Figure 11 refresh interval in )×4)".

[0127] The third row address generators 531 to 534 can be initialized at different times. For example, the third row address generators 531 to 534 can be initialized at each of the times tf0, tf1, tf2, and tf3 and can start operating. For example, the third row address generators 531 to 534 can sequentially output candidate addresses at each time of the interference source row refresh operations F0 to F7. For example, the third row address generator 531 can send the candidate address B at time tf4, the third row address generator 532 can send the candidate address C at time tf5, the third row address generator 533 can send the candidate address D at time tf6, and the third row address generator 534 can send the candidate address E at time tf7.

[0128] Figures 5 to 7 The content of to Figures 5 to 7 can equally apply to the configuration where the row address checker 550 compares the candidate addresses of the first row address generator 510 and the second row address generator 520. For example, the comparison operation (S31) of the row address checker 550 can correspond to Figure 7 the comparison operation (S11) of Figure 7 . Therefore, overlapping descriptions will be omitted.

[0129] The row address checker 550 can compare the candidate addresses of the second row address generator 520 and the third row address generator 530. For example, the row address checker 550 can compare the candidate addresses of the second row address generator 521 and the third row address generators 531 and 533, and compare the candidate addresses of the second row address generator 522 and the third row address generators 532 and 534.

[0130] The row address checker 550 can compare the previous candidate address B of the second row address generator 521 with the candidate address B of the third row address generator 531 at time tf4 (S32). The candidate address B of the second row address generator 521 to be compared can be the candidate address B output by the second row address generator 521 at a previous time (or the immediately preceding time, i.e., at time tf2). For example, the row address checker 550 can store the candidate addresses output from the first row address generator 510 to the third row address generator 530. In some embodiments, the row address checker 550 can store the candidate addresses output from the first row address generator 510 and the second row address generator 520.

[0131] The row address checker 550 can confirm that the candidate address B matches and determine that the row address generators 521 and 531 are working properly. The row address checker 550 can output the candidate address E of the first row address generator 510 as the interference source row address AGRA.

[0132] The row address checker 550 may send a reference address change signal to the third row address generator 531. The reference address change signal may include the candidate address E of the first row address generator 510 at time tf4. The third row address generator 531 may change the reference address to E based on the reference address change signal. The row address checker 550 may confirm at time tf4 that the candidate addresses D of the first row address generator 510 and the second row address generator 521 match, and may also send a reference address change signal to the second row address generator 521. The second row address generator 521 may change the reference address to E based on the reference address change signal.

[0133] Similarly, the row address checker 550 checks at times tf5 to tf7 that the candidate addresses of the first row address generator 510 to the third row address generator 530 match, and determines that the first row address generator 510 to the third row address generator 530 are operating normally. The row address checker 550 may output the candidate addresses E, F, G, and H of the first row address generator 510 as the disturbance source row addresses AGRA, and change the reference addresses of the second row address generator 520 and the third row address generator 530 to E, F, G, and H. In this way, the row hammer management circuit 500 can be protected from disturbance source patterns shorter than the refresh interval.

[0134] Figure 13 is a diagram for describing the timing of the refresh interval and the disturbance source pattern according to an embodiment. Figure 14 is a diagram for describing the disturbance source row refresh operation of the row hammer management circuit according to an embodiment.

[0135] Reference Figure 10 and Figure 13 , according to an embodiment, the row address checker 550 may perform a disturbance source row refresh operation at the refresh interval. For example, the row address checker 550 may perform a disturbance source row refresh operation at times t1, t5, t8, t11, and t14. In some embodiments, a normal refresh operation or a TRR operation may be performed between times t1, t5, t8, t11, and t14. In some embodiments, the refresh interval may be Figure 3 an integer multiple of the base refresh rate time tREFi.

[0136] The row address checker 550 may receive a disturbance source pattern from time t2 to t6. The disturbance source pattern may have a consistent row distribution type. In other words, the disturbance source pattern may be a pattern that repeatedly activates a specific number of rows. In an embodiment, the disturbance source pattern may be longer than the "refresh interval" and shorter than (or shorter than or equal to) "refresh interval × 2". The row address checker 550 may process the disturbance source rows of the disturbance source pattern at times t8, t11, and t14.

[0137] ReferenceFigure 10 , Figure 13 and Figure 14 , according to the embodiment, the row hammer management circuit 500 can perform interference source row refresh operations F0 to F6 at times tf0 to tf6.

[0138] The first row address generator 510 to the third row address generator 530 can send candidate addresses B to H to the row address checker 550 at times tf0 to tf6. In the embodiment, Figure 14 the times tf4, tf5, and tf6 in Figure 13 can correspond to the times t1, t5, and t8 in

[0139] The operations of the row hammer management circuit 500 at times tf0 to tf4 can be the same as those in Figure 12 and Figure 14 . Therefore, overlapping descriptions will be omitted.

[0140] Because the interference source pattern is longer than the refresh interval, the first row address generator 510 that determines candidate addresses based on the refresh interval may determine incorrect candidate addresses. For example, the first row address generator 510 can output candidate address G at time tf5 based on the row address received from time tf4 to time tf5 and the reference address E. At time tf5, candidate address G is not the comparison target, so it may not be possible to determine whether candidate address G is incorrect.

[0141] The row address checker 550 can compare the previous candidate address E of the first row address generator 510 with the candidate address E of the second row address generator 522 at time tf5, and compare the previous candidate address C of the second row address generator 522 with the candidate address C of the third row address generator 532. The row address checker 550 can confirm that candidate addresses E and C match. The row address checker 550 can output the candidate address G of the first row address generator 510 as the interference source row address AGRA. The row address checker 550 can change the reference addresses of the second row address generator 522 and the third row address generator 532 to the candidate address G of the first row address generator 510.

[0142] The row address checker 550 can compare the previous candidate address G of the first row address generator 510 with the candidate address F of the second row address generator 521 at time tf6 (S41). Because candidate addresses G and F do not match, the row address checker 550 can determine that the first row address generator 510 at the previous stage (stage 1) is operating abnormally. That is, when the candidate addresses do not match, the row address checker 550 can determine that the row address generator at the previous stage is abnormal. In Figure 14In the embodiment, the interference source pattern is longer than the "refresh interval" and shorter than (or shorter than or equal to) "refresh interval × 2", so the second row address generator 520 can normally output candidate addresses.

[0143] The row address checker 550 can change the reference address of the first row address generator 510 to the candidate address F (S42) of the second row address generator 521. That is, the first row address generator 510 outputs the candidate address H at time tf6, but generates the candidate address H based on the incorrect candidate address G at time tf5, so the reference address is changed to F.

[0144] The row address checker 550 can initialize the second row address generator 522 and the third row address generator 532 (S43 and S44) whose reference addresses are changed based on the candidate address G of the first row address generator 510. For example, the row address checker 450 can deactivate the candidate address to be output by the second row address generator 522 at a time (e.g., tf7) after time tf6. The row address checker 450 can deactivate the candidate address to be output by the third row address generator 532 at a time (e.g., tf9) after time tf6.

[0145] Because the row address checker 550 determines in the comparison operation that the first row address generator 510 is abnormal (S41), it can output the candidate address F of the second row address generator 521 as the interference source row address AGRA. In this way, the row hammering management circuit 500 can be protected from the interference source pattern longer than the refresh interval.

[0146] Figure 15 is a diagram for describing the timing of the refresh interval and the interference source pattern according to an embodiment. Figure 16 is a diagram for describing the interference source row refresh operation of the row hammering management circuit according to an embodiment.

[0147] Reference Figure 10 and Figure 15 , according to the embodiment, the row address checker 550 can perform the interference source row refresh operation at the refresh interval. That is, the row address checker 550 can perform the interference source row refresh operation at times t1, t5, t8, t11, and t14. In some embodiments, a normal refresh operation or a TRR operation can be performed between times t1, t5, t8, t11, and t14. In some embodiments, the refresh interval can be Figure 3 an integer multiple of the basic refresh rate time tREFi of

[0148] The row address checker 550 may receive a disturbance source pattern from time t2 to t10. The disturbance source pattern may have a consistent row distribution type. In other words, the disturbance source pattern may be a pattern that repeatedly activates a specific number of rows. In an embodiment, the disturbance source pattern may be longer than "refresh interval × 2" and shorter than (or shorter than or equal to) "refresh interval × 4". The row address checker 550 may process the disturbance source rows of the disturbance source pattern at times t8, t11, and t14.

[0149] See Figure 10 , Figure 15 and Figure 16 , the row hammer management circuit 500 according to an embodiment may perform disturbance source row refresh operations F0 to F7 at times tf0 to tf7.

[0150] The first row address generator 510 to the third row address generator 530 may send candidate addresses B to G, K, L, and N to the row address checker 550 at times tf0 to tf7. In an embodiment, Figure 16 times tf3, tf4, tf5, tf6, and tf7 in Figure 15 may correspond to times t1, t5, t8, t11, and t14 in

[0151] The operations of the row hammer management circuit 500 at times tf0 to tf3 may be the same as those in Figure 14 and Figure 16 . Therefore, overlapping descriptions will be omitted.

[0152] Since the disturbance source pattern is longer than "refresh interval × 2", the first row address generator 510 that determines candidate addresses based on the refresh interval or the second row address generator 520 that determines candidate addresses based on "refresh interval × 2" may determine incorrect candidate addresses. For example, the first row address generator 510 may output candidate address F at time tf4 based on the row address received from time tf3 to time tf4 and the reference address D. At time tf4, candidate address F is not a comparison target, so it may not be possible to determine whether candidate address F is incorrect.

[0153] The row address checker 550 may compare the previous candidate address D of the first row address generator 510 with the candidate address D of the second row address generator 521 at time tf4, and compare the previous candidate address B of the second row address generator 521 with the candidate address B of the third row address generator 531. The row address checker 550 may confirm that candidate addresses D and B match. The row address checker 550 may output the candidate address F of the first row address generator 510 as the disturbance source row address AGRA. The row address checker 550 may change the reference addresses of the second row address generator 521 and the third row address generator 531 to the candidate address F of the first row address generator 510.

[0154] In addition, the second row address generator 521 may output a candidate address G at time tf5 based on the row address received from time tf3 to time tf5 and the reference address D. At time tf5, the candidate address G is not the comparison target, so it may not be possible to determine whether the candidate address G is incorrect.

[0155] The row address checker 550 may compare the previous candidate address F of the first row address generator 510 with the candidate address G of the second row address generator 522 at time tf5. Since the candidate addresses F and G do not match, the row address checker 550 may determine that the first row address generator 510 at the previous stage (stage 1) is operating abnormally. That is, when the candidate addresses do not match, the row address checker 550 may determine that the row address generator at the previous stage is abnormal.

[0156] The row address checker 550 may change the reference address of the first row address generator 510 to the candidate address G of the second row address generator 521. That is, the first row address generator 510 outputs a candidate address K at time tf5, but generates the candidate address K based on the incorrect candidate address F at time tf4, so the reference address is changed to G.

[0157] The row address checker 550 may initialize the second row address generator 521 and the third row address generator 531 whose reference addresses are changed based on the candidate address F of the first row address generator 510. The row address checker 550 may set the reference address of the second row address generator 521 to the candidate address L of the first row address generator 510 at time tf6. The second row address generator 521 may output a candidate address based on the reference address L.

[0158] The row address checker 550 may compare the previous candidate address C of the second row address generator 521 with the candidate address C of the third row address generator 532 at time tf5. Since the candidate addresses C match, the row address checker 550 may change the reference address of the third row address generator 532 to G. The row address checker 550 may output the candidate address G of the second row address generator 521 as the interference source row address AGRA.

[0159] The row address checker 550 may compare the previous candidate address D of the second row address generator 521 with the candidate address D of the third row address generator 533 at time tf6. Since the candidate addresses D match, the row address checker 550 may output the candidate address L of the first row address generator 510 as the interference source row address AGRA. The row address checker 550 may change the reference address of the third row address generator 533 to the candidate address L of the first row address generator 510. At time tf6, the second row address generator 521 is in the initialization state, so the candidate addresses of the first row address generator 510 and the second row address generator 521 may not be compared. The row address checker 550 may determine the candidate address L of the first row address generator 510 as the reference address of the second row address generator 521.

[0160] The row address checker 550 may compare the previous candidate address L of the first row address generator 510 with the candidate address K of the second row address generator 521 at time tf7 (S51). Since the candidate addresses L and K do not match, the row address checker 550 may determine that the first row address generator 510 at the previous stage (stage 1) is operating abnormally.

[0161] The row address checker 550 may change the reference address of the first row address generator 510 to the candidate address K of the second row address generator 521 (S52). That is, the first row address generator 510 outputs the candidate address N at time tf7, but generates the candidate address N based on the incorrect candidate address L at time tf6, so the reference address is changed to K.

[0162] The row address checker 550 may compare the previous candidate address G of the second row address generator 522 with the candidate address E of the third row address generator 534 at time tf7. Since the candidate addresses G and E do not match, the row address checker 550 may determine that the second row address generator 522 at the previous stage (stage 2) is operating abnormally. In Figure 16 the embodiment, the interference source pattern is longer than "refresh interval × 2" and shorter than (or shorter than or equal to) "refresh interval × 4", so the third row address generator 530 may normally output the candidate address.

[0163] The row address checker 550 may change the reference addresses of the first row address generator 510 and the second row address generator 522 to the candidate address E of the third row address generator 534. That is, the candidate addresses N and K of the first row address generator 510 and the second row address generator 522 at time tf7 are incorrect, so the reference addresses are changed to E.

[0164] In addition, the row address checker 550 can initialize the second row address generator 521 and the third row address generators 531, 532, and 533 (S56, S57, S58, and S59). The second row address generator 521 and the third row address generators 531, 532, 533 can be initialized because they generate candidate addresses based on incorrect reference addresses F, G, and L from time tf4 to tf6.

[0165] Because the row address checker 550 determines that the second row address generator 522 is abnormal (S51) in the comparison operation, it can output the candidate address E of the third row address generator 534 as the interference source row address AGRA. In this way, the row hammer management circuit 500 can be protected from interference source patterns longer than "refresh interval × 2".

[0166] Figure 17 is a circuit diagram of a row hammer management circuit according to an embodiment.

[0167] Reference Figure 17 , the row hammer management circuit 600 according to an embodiment can include a first row address generator 610, second row address generators 621 and 622, and a row address checker 650. The row hammer management circuit 600 can receive an interference source pattern.

[0168] The first row address generator 610 can receive the row address R x , the monitoring signal CMD1, the activation signal Act, and the reference address R pre,in . The first row address generator 610 can store the candidate address R based on the received signals f,out , and output the candidate address R in response to the monitoring signal CMD1 f,out . The monitoring signal CMD1 can be a signal indicating an interference source row refresh operation. The monitoring signal CMD1 can be a signal corresponding to an interference source row refresh command signal (e.g., generated by the command decoder 220 or the refresh control circuit 290 in Figure 2 ). The monitoring signal CMD1 can have a period corresponding to a first monitoring length. For example, the first row address generator 610 can output the candidate address R whenever the interference source row refresh command signal is received f,out . The configuration of the first row address generator 610 outputting the candidate address R will be described later with reference to Figure 18 and Figure 19 . f,out

[0169] The second row address generators 621 and 622 can receive the row address R x , the monitoring signals CMD2 and CMD3, the activation signal Act, the mode control signal M in , and the reference address R pre,inThe second row address generators 621 and 622 can store candidate addresses R based on the received signals f,out and output candidate addresses R in response to monitoring signals CMD2 and CMD3 f,out The monitoring signals CMD2 and CMD3 can be signals generated based on an interference source row refresh command signal and a second monitoring length. The monitoring signals CMD2 and CMD3 can have a period corresponding to the second monitoring length. For example, the second row address generators 621 and 622 can alternately output candidate addresses R at different interference source row refresh times f,out

[0170] The second row address generators 621 and 622 can output a mode confirmation signal M to the row address checker 650 in response to a mode control signal M in out When the second row address generators 621 and 622 receive the mode control signal M in they can also output the mode confirmation signal M when outputting the candidate address R fout out

[0171] When the row address checker 650 receives the mode confirmation signal M out it can ignore the candidate address R f,out without using the candidate address R f,out For example, when the row address checker 650 receives the mode confirmation signal M from the second row address generator 621 out it can not use the candidate address R of the second row address generator 621 f,out In this case, the mode confirmation signal M out can be a signal for initialization. The row address checker 650 can receive the mode confirmation signal M from the second row address generator 621 out and send a new reference address R to the second row address generator 621 pre,in

[0172] In some embodiments, the second row address generators 621 and 622 and the row address checker 650 can operate without the mode control signal M in and the mode confirmation signal M out For example, the row address checker 650 can compare the candidate addresses R f,out and determine the second row address generator (e.g., 621) to be initialized. Even if the row address checker 650 receives the candidate address R from the second row address generator 621 f,out it may not be used in the comparison operation. The row address checker 650 can send a new reference address R to the second row address generator 621 pre,in ​​​​​​

[0173] The row address checker 650 can receive candidate addresses R from the first row address generator 610 and the second row address generators 621 and 622 f,out . The row address checker 650 can generate a disturbance source row address AGRA based on the candidate addresses R f,out . In an embodiment, the row address checker 650 can output one of the candidate addresses R of the row address generators 610, 621, and 622 as the disturbance source row address AGRA. When the row address checker 650 receives the monitoring signal CMD1, it can output the disturbance source row address AGRA. For example, the row address checker 650 can output the disturbance source row address AGRA whenever a disturbance source refresh command signal occurs. The configuration in which the row address checker 650 determines the disturbance source row address AGRA can be applied in the same manner as described in reference f,out . Figures 5 to 9 . In Figure 17 , the row hammer management circuit 600 is shown to include row address generators 610, 621, and 622 of two stages (a first stage and a second stage), but the embodiment is not necessarily limited thereto, and the row hammer management circuit 600 can also include row address generators of stages greater than the second stage.

[0174] Figure 18 is a block diagram of a row address generator according to an embodiment.

[0175] Reference Figure 18 , the first row address generator 700 according to an embodiment includes a register control circuit 710, a first register 720, a first comparator 730, a second register 740, a second comparator 750, and a flag generation circuit 760. The first row address generator 700 has a first monitoring length and can receive a disturbance source pattern that is shorter than or equal to the first monitoring length.

[0176] The first row address generator 700 can receive an input row address ROW_ADD and a monitoring signal CMD1, and provide a candidate address CADD for protection against a disturbance source pattern based on the input row address ROW_ADD and the monitoring signal CMD1. The input row address ROW_ADD can correspond to the row address R in Figure 17 . The candidate address CADD can correspond to the candidate address R in x . Figure 17 . f,out .

[0177] The register control circuit 710 can control the second register 740 based on the input row address ROW_ADD, the monitoring signal CMD1, a first comparison result signal CR1, a second comparison result signal CR2, and a flag signal FLAG.

[0178] The monitoring signal CMD1 can indicate monitoring in a cycle of a first monitoring length. For example, the monitoring signal CMD1 can correspond to an interference source row refresh command signal. For example, in Figure 6 the monitoring signal CMD1 can have a first level (e.g., high) at times t1, t5, and t8, and a second level (e.g., low) at other times.

[0179] In some embodiments, when the input row address ROW_ADD is first input during the monitoring period, the register control circuit 710 can provide the input row address ROW_ADD to the second register 740. The second register 740 can store the input row address ROW_ADD. The first input row address ROW_ADD can be referred to as the first input row address. When the first input row address is input, the flag signal FLAG can have a first bit value. For example, the first bit value can be "0" and the second bit value can be "1", but is not limited thereto. Hereinafter, it is assumed that the first bit value of the flag signal FLAG is "0" and the second bit value is "1".

[0180] In some embodiments, when the first input row address is less than or equal to the reference address RPRE (e.g., R pre,in ), the flag signal FLAG can have a first bit value. At the same time, when the first input row address is greater than the reference address RPRE, the flag signal FLAG can have a second bit value.

[0181] In some embodiments, the flag signal FLAG has a first bit value, and the input row address ROW_ADD input after the first input row address during the monitoring period can be greater than the reference address RPRE. In this case, the register control circuit 710 can provide the input row address ROW_ADD to the second register 740 so that the second register 740 stores the input row address ROW_ADD. The bit value of the flag signal FLAG can change from the first bit value to the second bit value. The fact that one row address is greater than another row address can, for example, mean that the address value of the row address is relatively large or the number of row addresses is relatively large.

[0182] In some embodiments, the flag signal FLAG can have a first bit value, the input row address ROW_ADD input after the first input row address can be less than or equal to the reference address RPRE, and the input row address ROW_ADD can be less than or equal to the row address RFIND stored in the second register 740. In this case, the register control circuit 710 can provide the input row address ROW_ADD to the second register 740 so that the second register 740 stores the input row address ROW_ADD. The flag signal FLAG can maintain the first bit value.

[0183] In some embodiments, the flag signal FLAG may have a first bit value, and the input row address ROW_ADD input after the first input row address may be less than or equal to the reference address RPRE and greater than the row address RFIND stored in the second register 740. In this case, the register control circuit 710 may wait without storing the input row address ROW_ADD in the second register 740. The flag signal FLAG may maintain the first bit value.

[0184] In some embodiments, the flag signal FLAG may have a second bit value, and the input row address ROW_ADD input after the first input row address may be greater than the reference address RPRE and less than the row address RFIND stored in the second register 740. In this case, the register control circuit 710 may provide the input row address ROW_ADD to the second register 740 such that the second register 740 stores the input row address ROW_ADD. The flag signal FLAG may maintain the second bit value.

[0185] In some embodiments, the register control circuit 710 may control the second register 740 such that the second register 740 provides the row address RFIND to the first register 720 in response to the monitoring signal CMD1. The register control circuit 710 may control the second register 740 in response to the monitoring signal CMD1 such that the second register 740 outputs the row address RFIND as the candidate address CADD. The second register 740 may output the candidate address CADD to the row address checker. In this case, the flag signal FLAG may have an initial value. The initial value may be, for example, the first bit value. However, it is not limited thereto.

[0186] The first register 720 may store the reference address RPRE. The reference address RPRE may be the row address that has been detected as the candidate address CADD in the previous monitoring period of the monitoring period. The first register 720 may provide the reference address RPRE to the first comparator 730. In some embodiments, the first register 720 may store the row address RFIND output from the second register 740 as the reference address RPRE. In this specification, the row address stored in the first register 720 may be referred to as the reference address RPRE.

[0187] The first register 720 may receive a reference address change signal from the row address checker. The first register 720 may change the reference address RPRE based on the reference address change signal.

[0188] The first comparator 730 may compare the value received from the memory controller (e.g., Figure 1The input row address ROW_ADD provided in (120) is compared with the reference address RPRE, and a first comparison result signal CR1 is output. The first comparison result signal CR1 can represent the comparison result between the input row address ROW_ADD and the reference address RPRE. For example, when the input row address ROW_ADD is less than or equal to the reference address RPRE, the first comparison result signal CR1 can have a first value. As another example, when the input row address ROW_ADD is greater than the reference address RPRE, the first comparison result signal CR1 can have a second value different from the first value. In an embodiment, the first value and the second value can be expressed as bit values, but are not limited thereto. The first comparison result signal CR1 can be provided to the register control circuit 710 and the flag generation circuit 760. The first comparator 730 can be implemented as a digital comparator, but is not limited thereto.

[0189] The second register 740 can store the input row address ROW_ADD under the control of the register control circuit 710. The second register 740 can provide the stored row address RFIND to the second comparator 750. The second register 740 can output the stored row address RFIND under the control of the register control circuit 710. The output row address RFIND can be provided to the first register 720, and / or the output row address RFINE can be provided to the row address checker as the candidate address CADD.

[0190] In some embodiments, during the monitoring period, the input row address ROW_ADD can be stored in the second register 740 as a candidate for the candidate address CADD. That is, the input row address ROW_ADD can be a candidate for the candidate address CADD, and the candidate address CADD can be a candidate for the interference source row address (e.g., Figure 4 AGRA in). The row address RFIND stored in the second register 740 in response to the monitoring signal CMD1 can be output as the candidate address CADD. For example, when performing an interference source row refresh operation, the row address RFIND can be output as the candidate address CADD.

[0191] In some embodiments, the input row address ROW_ADD detected as the candidate address CADD may be greater than the reference address RPRE. Additionally, the number of input row addresses ROW_ADD detected as the candidate address CADD within a specific monitoring period may be 1. Thus, the candidate address CADD greater than the reference address RPRE can be detected one by one during each monitoring period. In some embodiments, the input row addresses ROW_ADD detected as the candidate address CADD greater than the reference address RPRE may be sequentially stored in the second register 740. Here, the sequential storage order is, for example, an increasing order, and in this case, the increasing order may mean that the number of row addresses gradually increases. However, it is not limited thereto.

[0192] The second comparator 750 may compare the input row address ROW_ADD with the row address RFIND stored in the second register 740 and output a second comparison result signal CR2. The second comparison result signal CR2 may represent the comparison result between the input row address ROW_ADD and the row address RFIND.

[0193] For example, when the input row address ROW_ADD is less than the row address RFIND, the second comparison result signal CR2 may have a third value. As another example, when the input row address ROW_ADD is greater than or equal to the row address RFIND, the second comparison result signal CR2 may have a fourth value different from the third value. In an embodiment, the third value and the fourth value may be expressed as bit values, but it is not limited thereto. The second comparison result signal CR2 may be provided to the register control circuit 710 and the flag generation circuit 760. The second comparator 750 may be implemented as a digital comparator, but it is not limited thereto.

[0194] The flag generation circuit 760 may output a flag signal FLAG based on the monitoring signal CMD1, the first comparison result signal CR1, and the second comparison result signal CR2. In some embodiments, if the input row address ROW_ADD is less than or equal to the reference address RPRE, the flag generation circuit 760 may output a flag signal FLAG having a first bit value. In some embodiments, when the input row address ROW_ADD is greater than the reference address RPRE while the flag signal FLAG has the first bit value, the flag generation circuit 760 may output a flag signal FLAG having a second bit value.

[0195] In some embodiments, the flag generation circuit 760 may initialize the flag signal FLAG in response to the monitoring signal CMD1. In this case, the flag signal FLAG may have an initial value, and the initial value may be, for example, the first bit value.

[0196] The flag signal FLAG can be a signal that indicates the operation of the first mode or the second mode by having a first bit value or a second bit value. In an embodiment, when the flag signal FLAG has the first bit value, the first row address generator 700 can operate in the first mode. The first mode can be a mode of detecting the first minimum input row address among a plurality of input row addresses ROW_ADD. In another embodiment, when the flag signal FLAG has the second bit value, the first row address generator 700 can operate in the second mode. The second mode can be a mode of detecting the second minimum input row address among the input row addresses ROW_ADD that are greater than the reference address Rpre.

[0197] The flag generation circuit 760 can include a mode control circuit 761 and a status register 762. The mode control circuit 761 can control the status register 762 based on the first comparison result signal CR1, the second comparison result signal CR2, and the monitoring signal CMD1.

[0198] In some embodiments, the mode control circuit 761 can control the status register 762 to output the flag signal FLAG having an initial value in response to the monitoring signal CMD1. The initial value can be, for example, the first bit value.

[0199] In some embodiments, when the first comparison result signal CR1 has a first value in a state where the flag signal FLAG has the initial value, the mode control circuit 761 can control the status register 762 to output the flag signal FLAG having the first bit value.

[0200] In some embodiments, when the first comparison result signal CR1 has a second value in a state where the flag signal FLAG has the initial value, the mode control circuit 761 can control the status register 762 to output the flag signal FLAG having the second bit value.

[0201] In some embodiments, when the first comparison result signal CR1 has a first value and the second comparison result signal CR2 has a third value in a state where the flag signal FLAG has the first bit value, the mode control circuit 761 can control the status register 762 to output the flag signal FLAG having the first bit value.

[0202] As described above, the first row address generator 700 has the advantage of efficiently controlling the row hammer by including a register for storing the address that has been detected as the candidate address CADD and a register for storing the address to be detected as the candidate address CADD.

[0203] In addition, according to the above description, the number of registers included in the first row address generator 700 is reduced, which has the effect of improving the integration of the memory device.

[0204] Figure 19It is a diagram for describing the timing of operations for managing row hammering according to an embodiment.

[0205] Reference Figure 18 and Figure 19 , according to an embodiment, the first row address generator 700 can receive an internal command signal ICS. The internal command signal ICS can include a monitoring signal CMD1 and a row address. The monitoring signal CMD1 can be sent at a period of a first monitoring length. The row address can include a disturbance source pattern.

[0206] For example, assume that the row hammer disturbance source pattern is a pattern that performs row hammer attacks more than once on memory cell rows with row addresses 10R10, 30R30, 100R100, and 1000R1000 respectively. The period of the disturbance source row refresh operation can correspond to the type of row address that undergoes the row hammer attack. For example, in Figure 19 the shown row hammer disturbance source pattern, there are four types of row addresses that undergo the row hammer attack, so Figure 19 the shown refresh operation period can be 4. The monitoring signal CMD1 can be input in each period of the refresh operation (e.g., times tf0, tf1, tf2, and tf3).

[0207] In an embodiment, Figure 17 the monitoring signal CMD2 can be input at times tf0 and tf2, and the monitoring signal CMD3 can be input at times tf1 and tf3. For example, the monitoring signals CMD2 and CMD3 have a second monitoring length and can be alternately input at different refresh times.

[0208] The total number of accesses within the period of the refresh operation can correspond to the product of the period and the type of row address that undergoes the row hammer attack. For example, within the period corresponding to the time interval between one monitoring signal CMD1 and another monitoring signal CMD1 (e.g., between time tf0 and time tf1), the number of the access count ACC CNT is "6", so the total number of accesses within the period of the refresh operation can be "24 (= 6 × 4)". However, it is not limited thereto.

[0209] Reference Figure 19 , the monitoring period can be, for example, the period from after the monitoring signal CMD1 is input to before the next monitoring signal CMD1 is input. Figure 19 The first monitoring period pMNT1, the second monitoring period pMNT2, and the third monitoring period pMNT3 are shown, and each of the monitoring periods pMNT1 to pMNT3 corresponds to Figure 18 the first monitoring length in

[0210] Assume that the initial value of the reference address RPRE is the row address 30R30.

[0211] Whenever each of the row addresses R10, R30, R100, and R1000 is input to the first row address generator 700, the access count ACC CNT can be incremented by +1. The access count ACC CNT can be initialized to an initial value in response to the monitoring signal CMD1. Refer to Figure 18 , for example, when the monitoring signal CMD1 is input to the first row address generator 700, the access count ACC CNT can be initialized to "0".

[0212] When the monitoring signal CMD1 is input, the flag signal FLAG can be a first bit value (e.g., "0").

[0213] Refer to Figure 19 Shown as the first monitoring period pMNT1, within the first monitoring period pMNT1, the row addresses 1000R1000, 30R30, 100R100, 10R10, 30R30, and 100R100 can be sequentially input. In some embodiments, the first row address generator 700 can temporarily store the first input row address input first within the monitoring period as a candidate for the candidate address CADD. Refer to Figure 19 , for example, within the first monitoring period pMNT1, the first input row address is the row address 1000R1000. The register control circuit 710 stores the row address 1000R1000 in the second register 740. The row address 1000R1000 is stored in the second register 740 as a candidate for the candidate address CADD (e.g., Figure 19 shown as the row address RFIND).

[0214] In some embodiments, the first row address generator 700 can operate one of the first mode and the second mode based on the first input row address and the reference address RPRE. Refer to Figure 19 , for example, the row address 1000R1000 is greater than the row address 30R30, so the bit value of the flag signal FLAG is a second bit value (e.g., "1"). Since the flag signal FLAG has the second bit value, the second mode can be operated.

[0215] In some embodiments, when the input row address input after the first input row address in the second mode is greater than the reference address RPRE and the input row address is less than the temporarily stored row address (as a candidate for the candidate address CADD), the first row address generator 700 can temporarily store the input row address as a candidate for the candidate address CADD.

[0216] In an embodiment, in the second mode, when the input row address is greater than the reference address RPRE and less than the row address RFIND already stored in the second register 740, the input row address may be stored in the second register 740.

[0217] Reference Figure 19 , for example, the row address 30R30 input after the row address 1000R1000 is the same as the reference address RPRE. Therefore, the row address 30R30 is not stored in the second register 740. The row address 100R100 input after the row address 30R30 is greater than the row address 30R30 which is the reference address RPRE. The row address 100R100 is less than the row address 1000R1000 which is the row address RFIND already stored in the second register 740. Therefore, the row address 100R100 is stored in the second register 740. In this way, the row addresses 10R10, 30R30, and 100R100 are sequentially input, and according to the size condition in the second mode described above, the row address RFIND stored in the second register 740 is the row address 100R100.

[0218] In some embodiments, in the second mode, the first row address generator 700 may output, in response to the monitoring signal CMD1, the row address temporarily stored during the monitoring period as the candidate address CADD.

[0219] As Figure 19 shown by the row address RFIND within the first monitoring period pMNT1, the row address 100R100 is detected as the candidate address CADD after the row address 30R30 within the first monitoring period pMNT1. The row address 100R100 may be output in response to the monitoring signal CMD1.

[0220] In some embodiments, the first row address generator 700 may detect, within the first monitoring period pMNT1, the first input row address greater than the reference address RPRE as the candidate address CADD among a plurality of input row addresses, and store the detected first input row address in the second register 740. In an embodiment, the first input row address (or the first row address) may be the smallest row address among the input row addresses (or row addresses) input during the first monitoring period.

[0221] Reference Figure 19, for example, among the row addresses 10R10, 30R30, 100R100, and 1000R1000 input during the first monitoring period, the row addresses greater than 30R30 that serve as the reference address RPRE are 100R100 and 1000R1000. The smallest row address among 100R100 and 1000R1000 is 100R100. Therefore, the first input row address (or the first row address) is 100R100.

[0222] In some embodiments, during the refresh operation after the first monitoring period pMNT1 (i.e., at time tf1), the first row address generator 700 may store the first input row address (or the first row address) as the reference address Rpre in the first register 720. Refer Figure 19 , for example, when the monitoring signal CMD1 is input after the first monitoring period pMNT1, the row address 100R100, which is the row address Rfind detected within the first monitoring period pMNT1, is stored as the reference address Rpre in the first register 720.

[0223] Refer Figure 19 Shown is the second monitoring period pMNT2 after the first monitoring period pMNT1. In the second monitoring period pMNT2, the row addresses 10R10, 100R100, 30R30, 1000R1000, 30R30, and 100R100 may be input sequentially.

[0224] In some embodiments, the first row address generator 700 may store the first input row address (or the first row address) as the reference address RPRE within the second monitoring period pMNT2. Refer Figure 19 , for example, the first input row address (or the first row address) is 100R100. Therefore, 100R100 is stored as the reference address RPRE in the first register 720 within the second monitoring period pMNT2. When the monitoring signal CMD1 is input, the flag signal FLAG may be a first bit value (e.g., "0"). The row address 10R10, which is the first input row address, is stored in the second register 740 (e.g., row address RFIND).

[0225] In some embodiments, when the first input row address is less than or equal to the reference address RPRE, the first row address generator 700 may run the first mode. Refer Figure 19, for example, since the row address 10R10 is less than the row address 100R100, the flag signal FLAG maintains the first bit value, and thus the first mode is run. Then, since the row address 100R100 and the row address 30R30 are each greater than the row address 10R10 (e.g., the row address RFIND) of the candidate memory as the candidate address CADD in the first mode, the bit value of the flag signal FLAG remains the first bit value.

[0226] In some embodiments, in the first mode, when the input row address input after the first input row address is greater than the reference address RPRE, the first row address generator 700 may temporarily store the input row address as a candidate for the candidate address CADD and run the second mode. Refer to Figure 19 , for example, the row address 1000R1000 input after the row address 30R30 is greater than the row address 100R100, so the row address 1000R1000 is stored in the second register 740. The bit value of the flag signal FLAG changes from the first bit value to the second bit value (e.g., "1"). In the second mode, the row address 30R30 input after the row address 1000R1000 is less than the reference address RPRE, and the row address 100R100 input after the row address 30R30 is the same as the reference address RPRE, so the row address RFIND stored in the second register 740 is maintained as the row address 1000R1000.

[0227] In some embodiments, the first row address generator 700 may detect a second input row address (or second row address) greater than the first input row address (or first row address) as the candidate address CADD within the second monitoring period pMNT2 and store the second input row address (or second row address) in the second register 740. In an embodiment, the second input row address (or second row address) may be the row address that is the second smallest among the row addresses input during the second monitoring period and less than the first input row address (or first row address).

[0228] Refer to Figure 19 , for example, the first input row address (or first row address) is the row address 100R100. Among the row addresses 10R10, 30R30, 100R100, and 1000R1000 input during the second monitoring period, the row address greater than the row address 100R100 is the row address 1000R1000. Therefore, the second input row address (or second row address) is the row address 1000R1000.

[0229] In some embodiments, during a refresh operation after the second monitoring period pMNT2, the first row address generator 700 may store a second input row address (or a second row address) as a reference address RPRE in the first register 720. Refer to Figure 19 , the row address 1000R1000 is stored as the reference address RPRE in the first register 720. When the monitoring signal CMD1 is input, the flag signal FLAG may be a first bit value (e.g., "0").

[0230] In some embodiments, during Figure 19 the third monitoring period pMNT3 after the second monitoring period pMNT2 shown, the row address 100R100 as the first input row address is stored in the second register 740 (e.g., row address Rfind).

[0231] In some embodiments, in the first mode, when an input row address input after the first input row address is less than or equal to the reference address Rpre and the input row address is less than or equal to the row address of the candidate temporary storage as the candidate address CADD, the first row address generator 700 may temporarily store the input row address as a candidate in the candidate address CADD.

[0232] For example, refer to Figure 19 , the row address 10R10 input after the row address 100R100 is less than the row address 1000R1000 and less than the row address 100R100. Therefore, the row address 10R10 is stored in the second register 740. In this case, the flag signal FLAG is maintained as the first bit value. In the first mode, the row addresses R30, R1000, R30, and R10 input after the row address 10 are less than the row address 1000R1000 as the reference address RPRE. The row addresses R30, R1000, R30, and R10 are greater than or equal to the row address 10R10 as the row address RFIND stored in the second register 740. Therefore, the row address 10R10 continues to be stored in the second register 740.

[0233] In some embodiments, when multiple input row addresses are less than or equal to the reference address RPRE, the first row address generator 700 may detect the smallest input row address among the multiple input row addresses as the candidate address CADD. For example, refer to Figure 19, during the third monitoring period pMNT3, the multiple input row addresses are row address 100R100, row address 10R10, row address 30R30, row address 1000R1000, row address 30R30, and row address 10R10. During the third monitoring period pMNT3, the reference address RPRE is row address 1000R1000. Thus, the smallest input row address among the multiple input row addresses is row address 10R10 and row address 10R10 is detected as the candidate address CADD. In response to the monitoring signal CMD1 input after the third monitoring period pMNT3, row address 10R10 is output as the candidate address CADD. Since no row address greater than row address 1000R1000 which is the reference address RPRE has been detected, the flag signal FLAG maintains the first bit value, and the first row address generator 700 can complete one cycle of monitoring. The first row address generator 700 can start monitoring from row address 10R10.

[0234] According to the above embodiments, there is an effect of improving the integration of the memory device by controlling various types of row hammers.

[0235] In addition, according to the above embodiments, the performance and reliability of the memory device can be improved by controlling various types of row hammers.

[0236] Figure 20 is a flowchart of a method for generating a disturbance source row address according to an embodiment.

[0237] Reference Figure 20 , a memory device according to an embodiment can generate a disturbance source row address.

[0238] The memory device can generate a candidate address based on a reference address and different monitoring information (S1810). The monitoring information can include a monitoring start time and a monitoring length. The monitoring start time corresponds to the disturbance source row refresh time, and the basic unit of the monitoring length can be the disturbance source row refresh interval. For example, the first monitoring length can correspond to the disturbance source row refresh interval, and the second monitoring length can correspond to "disturbance source row refresh interval × 2". The monitoring length can correspond to the monitoring level. For example, the first monitoring length can correspond to the first level (higher level), and the second monitoring length can correspond to the second level (lower level).

[0239] For example, the memory device can monitor input row addresses based on different monitoring start times and / or different monitoring lengths. For example, the memory device can perform monitoring based on the first monitoring length at the first refresh time, monitoring based on the second monitoring length at the first refresh time, and monitoring based on the second monitoring length at the second refresh time immediately following the first refresh time.

[0240] A memory device may perform monitoring by comparing a reference address and an input row address. As a result of the monitoring, the memory device may output one of the input row addresses as a candidate address. In an embodiment, the memory device may output the smallest address among the input row addresses that is greater than the reference address (or the immediately preceding interfering source row address) as the candidate address. In an embodiment, when there is no input row address greater than the reference address, the memory device may output the smallest address among the input row addresses as the candidate address.

[0241] The memory device may compare candidate addresses (S1820). In this case, the memory device may compare candidate addresses at different times. For example, the memory device may compare a higher-level candidate address at a previous time and a lower-level candidate address at the current time. That is, the memory device may store candidate addresses. When the candidate addresses match, the memory device may determine it as normal monitoring. When the candidate addresses do not match, the memory device may determine it as abnormal monitoring.

[0242] The memory device may modify the reference address based on the comparison result (S1830). Additionally, the memory device may determine the interfering source row address based on the comparison result (S1840).

[0243] In an embodiment, when the candidate addresses match (i.e., normal monitoring), the memory device may modify the lower-level reference address. The memory device may use the higher-level candidate address as the lower-level reference address. The memory device may output the higher-level candidate address as the interfering source row address. The memory device may generate a lower-level candidate address based on the new reference address.

[0244] In an embodiment, when the candidate addresses do not match (i.e., abnormal monitoring), the memory device may modify the higher-level reference address.

[0245] The memory device may use the lower-level candidate address as the higher-level reference address. The memory device may output the lower-level candidate address as the interfering source row address. The memory device may generate a higher-level candidate address based on the new reference address.

[0246] The memory device may refresh the memory cells of the rows corresponding to the row addresses adjacent to the row corresponding to the interfering source row address.

[0247] Figure 21 is a block diagram of a computing system according to an embodiment.

[0248] Reference Figure 21 , a computing system 1500 according to an embodiment includes a processor 1510, a memory 1520, a memory controller 1530, a storage device 1540, a communication interface 1550, and a bus 1560. The computing system 1500 may also include other general components.

[0249] The processor 1510 controls the overall operation of each component of the computing system 1500. The processor 1510 may be implemented as at least one of various processing units such as a central processing unit (CPU), an application processor (AP), and a graphics processing unit (GPU).

[0250] The memory 1520 stores various data and commands. The memory controller 1530 controls the transfer of data or commands to and from the memory 1520. The memory 1520 and / or the memory controller 1530 may perform the refresh operations described in Figures 1 to 20 For example, the memory 1520 may perform a disturbed source row refresh operation in response to a command from the memory controller 1530. The memory 1520 may further perform a normal refresh or a TRR. For example, the memory 1520 may generate candidate addresses based on different monitoring start times and / or different monitoring lengths. The memory 1520 may determine whether the candidate addresses match and determine the disturbed source row address based on the determination result. The memory 1520 may refresh the memory cells of the rows adjacent to the row corresponding to the disturbed source row address. The memory 1520 may protect against disturbed source patterns of various lengths by performing refreshes based on different monitoring start times and / or different monitoring lengths.

[0251] In some embodiments, the memory controller 1530 may be provided as a separate chip from the processor 1510. In some embodiments, the memory controller 1530 may be provided as an internal component of the processor 1510.

[0252] The storage device 1540 stores programs and data non-temporarily. In some embodiments, the storage device 1540 may be implemented as a non-volatile memory. The communication interface 1550 supports wired and wireless Internet communication of the computing system 1500. Additionally, the communication interface 1550 may support various communication methods other than Internet communication. The bus 1560 provides a communication function between the components of the computing system 1500. Depending on the communication protocol between the components, the bus 1560 may include at least one type of bus.

[0253] Figure 22 is a diagram showing a memory module according to an embodiment.

[0254] Reference Figure 22, according to an embodiment, the memory module 2000 may include a plurality of memory chips (e.g., DRAM), each memory chip including a memory cell array, a buffer chip (RCD) for routing transmit and receive signals to and from a memory controller or managing memory operations for the memory chip, and a power management chip (PMIC). The RCD may control the memory chip (DRAM) and the power management chip (PMIC) under the control of the memory controller. For example, the RCD may receive a command signal, a control signal, and a clock signal CLK from the memory controller.

[0255] The memory chips (DRAM) may each be connected to a corresponding data buffer among data buffers (DB) through corresponding data transmission lines, and may transmit and receive data signals and data strobe signals. The memory chips (DRAM) may each be connected to the data buffers (DB) through corresponding data transmission lines, and transmit and receive parity data and data strobe signals.

[0256] The memory module 2000 may include an electrically erasable programmable read-only memory (EEPROM). The EEPROM may include initial information or device information of the memory module 2000. For example, the EEPROM may include initial information or device information of the memory module 2000, such as module form, module configuration, storage capacity, module type, and operating environment. When a storage system including the memory module 2000 is booted, the memory controller may read the device information from the EEPROM and identify the memory module based on the read device information.

[0257] The memory module 2000 may include a plurality of ranks. In an embodiment, each rank may include eight bank groups. Each bank group may include four banks.

[0258] The memory module 2000 may perform the refresh operation described with reference to Figures 1 to 20 For example, the memory module 2000 may perform a disturbed source row refresh operation. For example, the memory module 2000 may generate candidate addresses based on different monitoring start times and / or different monitoring lengths. The memory module 2000 may determine whether the candidate addresses match and determine the disturbed source row address based on the determination result. The memory module 2000 may refresh the memory cells of the rows adjacent to the row corresponding to the disturbed source row address. The memory module 2000 may protect against disturbed source patterns of various lengths by performing refreshes based on different monitoring start times and / or different monitoring lengths.

[0259] Figure 23 is a diagram showing a semiconductor package according to an embodiment.

[0260] ReferenceFigure 23 , according to an embodiment, the semiconductor package 3000 can be a memory module, which includes at least one stacked semiconductor chip 3300 and a system-on-chip (SoC) 3400 mounted on a package substrate 3100 such as a printed circuit board. In some embodiments, an interposer layer 3200 can optionally be further provided on the package substrate 3100. The stacked semiconductor chip 3300 can be formed as a chip-on-chip (CoC).

[0261] The stacked semiconductor chip 3300 can include at least one memory chip 3320 stacked on a buffer chip 3310 such as a logic chip. The buffer chip 3310 and the at least one memory chip 3320 can be connected to each other through through-silicon vias (TSVs). The buffer chip 3310 can perform a training operation on the memory chip 3320. For example, the stacked semiconductor chip 3300 can be a high-bandwidth memory (HBM) of 500 GB / second to 1 TB / second or greater.

[0262] The at least one memory chip 3320 can perform the Figures 1 to 20 refresh operation described in the reference. For example, the at least one memory chip 3320 can perform a disturbed source row refresh operation. For example, the at least one memory chip 3320 can generate candidate addresses based on different monitoring start times and / or different monitoring lengths. The at least one memory chip 3320 can determine whether the candidate addresses match and determine the disturbed source row address based on the determination result. The at least one memory chip 3320 can refresh the memory cells of the rows adjacent to the row corresponding to the disturbed source row address. The at least one memory chip 3320 can be protected from disturbed source patterns of various lengths by performing refreshes based on different monitoring start times and / or different monitoring lengths.

[0263] In some embodiments, each component described in the reference Figures 1 to 23 or a combination of two or more components can be implemented as a digital circuit, a programmable or non-programmable logic device or array, or an application-specific integrated circuit (ASIC), etc. Although the embodiments of the present disclosure have been described in detail above, the scope of the present disclosure is not limited thereto, but may include several modifications and changes made by those skilled in the art using the basic concept of the present invention as defined in the appended claims.

Claims

1. A memory device, comprising: a memory cell array, the memory cell array comprising a plurality of memory cells; as well as a refresh control circuit configured to generate a refresh row address and perform a refresh operation on memory cells of a row corresponding to the refresh row address, Wherein, the refresh control circuit includes a row hammer management circuit, and the row hammer management circuit includes: a first row address generator configured to receive a first input row address during a first monitoring length and determine a first candidate address among the first input row addresses based on a first reference address; a second row address generator configured to receive a second input row address during a second monitoring length longer than the first monitoring length, and determine a second candidate address among the second input row addresses based on a second reference address; and a row address checker configured to determine an aggressor row address based on the first candidate address and the second candidate address, wherein the row corresponding to the refresh row address is adjacent to the row corresponding to the interference source row address, and The first monitoring length and the second monitoring length are both cycles for performing the refresh operation.

2. The memory device of claim 1, wherein: The first row address generator is further configured to send the first candidate address to the row address checker based on the first monitoring length as the cycle, The second row address generator is further configured to send the second candidate address to the row address checker based on the second monitoring length as the cycle, and The row address checker is further configured to store at least one of the first candidate address and the second candidate address.

3. The memory device of claim 2, wherein: The row address checker is further configured to compare the first candidate address at a first aggressor row refresh time with the second candidate address at a second aggressor row refresh time after the first aggressor row refresh time, and determine the aggressor row address based on the comparison result.

4. The memory device of claim 3, wherein: The row hammering management circuit is configured to cause the row address checker to determine the first candidate address at the second aggressor row refresh time as the aggressor row address when the first candidate address at the first aggressor row refresh time matches the second candidate address at the second aggressor row refresh time.

5. The memory device of claim 3, wherein: The row hammering management circuit is configured to cause the row address checker to change the second reference address to the first candidate address at the second aggressor row refresh time when the first candidate address at the first aggressor row refresh time matches the second candidate address at the second aggressor row refresh time.

6. The memory device of claim 3, wherein: The row hammering management circuit is configured to cause the row address checker to determine the second candidate address at the second aggressor row refresh time as the aggressor row address when the first candidate address at the first aggressor row refresh time does not match the second candidate address at the second aggressor row refresh time.

7. The memory device of claim 3, wherein: The row hammering management circuit is configured to cause the row address checker to change the first reference address to the second candidate address at the second aggressor row refresh time when the first candidate address at the first aggressor row refresh time does not match the second candidate address at the second aggressor row refresh time.

8. The memory device of claim 3, wherein: The second row address generator is further configured to monitor the second input row address during the second monitoring length starting from the first aggressor row refresh time, The row hammering management circuit further includes a third row address generator configured to determine a third candidate address by monitoring a third input row address during the second monitoring length starting from the second aggressor row refresh time after the first aggressor row refresh time, and The row address checker is further configured to determine the aggressor row address based on the first candidate address and one of the second candidate address and the third candidate address.

9. The memory device of claim 8, wherein: The row hammer management circuit is configured to cause the row address checker to deactivate the third candidate address when the first candidate address at the first aggressor row refresh time does not match the second candidate address at the second aggressor row refresh time.

10. The memory device of claim 9, wherein: The third row address generator is further configured to receive a mode control signal from the row address checker and send the third candidate address and a mode confirmation signal to the row address checker at a third aggressor row refresh time after the second aggressor row refresh time, and The row address checker is further configured to send the mode control signal to the third row address generator and deactivate the third candidate address based on the mode confirmation signal.

11. The memory device of claim 1 , further comprising: a third row address generator configured to receive a third input row address during a third monitoring length longer than the second monitoring length, and determine a third candidate address among the third input row addresses based on a third reference address, The row address checker is further configured to determine the interference source row address based on the first candidate address, the second candidate address and the third candidate address.

12. The memory device of claim 11, wherein: The row address checker is further configured to compare the first candidate address at a first time with the second candidate address at a second time, and to compare the second candidate address at a third time with the third candidate address at the second time.

13. The memory device of claim 12, wherein: The first time is earlier than the second time, and the third time is earlier than the first time.

14. The memory device of claim 13, wherein: The row hammer management circuit is configured to cause the row address checker to change the first reference address and the second reference address to the third candidate address at the second time, and to determine the third candidate address at the second time as the interference source row address when the second candidate address at the third time does not match the third candidate address at the second time.

15. The memory device of claim 13, wherein: The row hammer management circuit is configured to cause the row address checker to change the second reference address and the third reference address to the first candidate address at the second time, and to determine the first candidate address at the second time as the interference source row address, when the first candidate address at the first time matches the second candidate address at the second time and the second candidate address at the third time matches the third candidate address at the second time.

16. The memory device of claim 11, wherein: The first monitoring length corresponds to an interference source row refresh interval, and The third monitoring length corresponds to "interference source row refresh interval×4".

17. The memory device of claim 1, wherein: The first monitoring length corresponds to an interference source row refresh interval.

18. The memory device of claim 1, wherein: The second monitoring length corresponds to "interval of interference source row refresh × 2".

19. A memory device, the memory device comprising: a memory cell array, the memory cell array comprising a plurality of memory cells; as well as A refresh control circuit, wherein the refresh control circuit is configured to: Generate candidate addresses based on reference addresses and row addresses input during different monitoring lengths, generating an aggressor row address based on whether the candidate address matches, and outputting a refresh row address of a row adjacent to the row corresponding to the interference source row address, The memory device is configured to perform a refresh operation on memory cells in a row corresponding to the refresh row address, and The different monitoring lengths are all used to execute the cycles of the refresh operation.

20. A method for a refresh operation of a memory device, the method comprising: receiving row addresses during different monitoring lengths; generating a candidate address based on the reference address and the received row address; comparing the candidate addresses; modifying the reference address based on the comparison result; Determine the interference source row address based on the comparison result; as well as performing a refresh on memory cells of a row adjacent to a row corresponding to the aggressor row address, The different monitoring lengths are all used for a cycle of performing a refresh on the memory cells of the row adjacent to the row corresponding to the interference source row address.