Memory element and protection method thereof

By introducing protection circuits of random number generators and counters into DRAM, randomly selecting and protecting memory columns that may be attacked, solving the content leakage problem caused by the column hammer effect, and improving the security and efficiency of memory components.

CN120260641AActive Publication Date: 2025-07-04NAN YA TECH
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202410467596.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-02
Filing Date
2024-04-18
Publication Date
2025-07-04
Estimated Expiration
2044-04-18

AI Technical Summary

Technical Problem

The character lines in dynamic random access memory (DRAM) are susceptible to column hammer effects, resulting in leakage of column content of adjacent memory, which makes it difficult for the prior art to effectively protect.

Method used

A protection circuit consisting of a random number generator and a counter is adopted. By randomly selecting and protecting memory columns that may be attacked, the counter counts down from the random number, and obtains the attacked memory column address when the counter reaches zero, and protects it in subsequent update cycles.

Benefits of technology

Effectively prevent the column hammer effect, improve the security and effectiveness of memory components, and ensure that adjacent memory columns are not attacked during the update cycle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120260641A_ABST
    Figure CN120260641A_ABST
Patent Text Reader

Abstract

The invention provides a memory element and a protection method thereof. The memory element includes a random number generator, a counter, and a controller. The random number generator includes a first logic gate and a second logic gate configured to generate a first output and a second output according to the address of the first word line and the address of the first accessed word line, respectively. The random number generator also includes a switch configured to select one of the first output and the second output as a first number. The counter is configured to receive the first number and to countdown from the first number. The controller is configured to obtain a address of a second accessed wordline being accessed when the counter counts to zero, and update an adjacent wordline of the second accessed wordline during a second update period.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference

[0002] This application claims the priority of U.S. Patent Application No. 18 / 401,758 (i.e., the priority date is "January 2, 2024"), the content of which is incorporated herein by reference in its entirety. Technical Field

[0003] The present disclosure relates to a memory element and a method for protecting the same. In particular, it relates to a memory element including a protection circuit for protecting a word line. Background Art

[0004] A dynamic random access memory (DRAM) stores each bit of data in a separate capacitor. A simple DRAM cell includes a single transistor and a single capacitor. If charge is stored in the capacitor, the cell is said to store a logic high (HIGH), depending on the convention used. Then, if no charge is present, the cell is said to store a logic low (LOW). Since the charge in the capacitor dissipates over time, the DRAM system requires additional refresh circuitry to periodically refresh the charge stored in the capacitor. Since a capacitor can store only a very limited amount of charge, to quickly distinguish the difference between logic "1" and logic "0", each bit typically uses two bit lines (BL), where the first in the bit line pair is called a bit line true (BLT) and the other is called a bit line complement (BLC). The gate of the single transistor is controlled by a word line (WL).

[0005] Row hammer is a security issue stemming from unexpected and adverse side effects of DRAM, where memory cells electrically interact with each other by leaking charge, which may change the content of nearby memory columns (word lines) that are not addressed in the original memory access. Row hammer can be triggered by a specific memory access pattern that repeatedly and rapidly activates the same memory column (word line). Thus, the memory cells connected to adjacent word lines leak charge and it is difficult to maintain the original content through subsequent periodic refresh cycles. A malicious operator can exploit the row hammer effect to change the content of nearby memory columns, resulting in component failure. Therefore, it is necessary to develop a method for protecting the memory (especially its word lines) to mitigate the described problems.

[0006] The above description of "prior art" only provides background art and does not admit that the above description of "prior art" discloses the subject matter of the present disclosure, does not constitute the prior art of the present disclosure, and any description of the above "prior art" should not be regarded as any part of the present disclosure. Summary of the Invention

[0007] An embodiment of the present disclosure provides a memory element. The memory element includes a plurality of word lines, a random number generator, a counter, and a controller. The random number generator is configured to receive an address of a first word line and an address of a first accessed word line, wherein adjacent word lines of the first word line and the first accessed word line are updated during a first update period. The random number generator includes a first logic gate, a second logic gate, and a switch. The first logic gate is configured to generate a first output according to the address of the first word line and the address of the first accessed word line. The second logic gate is configured to generate a second output according to the address of the first word line and the address of the first accessed word line. The switch is electrically coupled to the first logic gate and the second logic gate for selecting one of the first output and the second output as a first number. The counter is electrically coupled to the random number generator, and the counter is configured to receive the first number and count down from the first number. The controller is configured to obtain an address of a second accessed word line being accessed when the counter counts down to zero from the first number, and update adjacent word lines of the second accessed word line during a second update period.

[0008] Another embodiment of the present disclosure provides a memory element. The memory element includes a plurality of word lines, a random number generator, a counter, an address register, and a controller. The random number generator is configured to receive an address of a first word line and an address of a first accessed word line, wherein adjacent word lines of the first word line and the first accessed word line are updated during a first update period. The random number generator includes a first logic gate, a second logic gate, and a switch. The first logic gate is configured to generate a first output according to the address of the first word line and the address of the first accessed word line. The second logic gate is configured to generate a second output according to the address of the first word line and the address of the first accessed word line. The switch is electrically coupled to the first logic gate and the second logic gate for selecting one of the first output and the second output as a first number. The counter is electrically coupled to the random number generator and is configured to receive the first number and count down from the first number. The address register is electrically coupled to the counter and is configured to store an address of a second accessed word line that is valid when the counter counts down to zero. The controller is configured to access the address register to obtain the address of the second accessed word line and protect adjacent word lines of the second accessed word line during a second update period.

[0009] Another embodiment of the present disclosure provides a method for protecting a memory element, wherein the memory element includes a plurality of word lines. The protection method includes generating, by a first logic gate, a first output according to an address of a first word line and an address of a first accessed word line, wherein adjacent word lines of the first word line and the first accessed word line are updated during a first update period; generating, by a second logic gate, a second output according to the address of the first word line and the address of the first accessed word line; selecting, by a multiplexer in response to a selection signal, one of the first output and the second output as a first number; counting down, by a counter, from the first number; when the counter counts to zero, obtaining, by a controller, an address of a second accessed word line being accessed; and updating, during a second update period, a second protected word line, wherein the second protected word line is adjacent to the second accessed word line.

[0010] Embodiments of the present disclosure provide a memory element having a protection circuit for selecting and protecting vulnerable word lines. Specifically, the protection circuit of the memory element can protect the word lines (memory cells) from column hammering. To trigger column hammering, a malicious operator would rapidly activate the same memory column, causing charge leakage on adjacent unactivated memory columns. This protection circuit provides a random number generator and a counter to randomly select and protect a memory column that may be attacked. The counter can be configured to count down from a random number generated by the random number generator. When the counter reaches zero, the address of the activated memory column can be obtained. In other words, the memory column is selected from the memory columns activated between update cycles. In this case, the selection pool includes the memory columns activated between update cycles. The random number generator can generate a random number based on the address of the last updated word line and the address of the last accessed word line (the selected word line that may be attacked) to increase the unpredictability of the random number. Specifically, the random number generator can include one or more logic gates that generate a random number based on the updated word line address and the target word line address in the previous update cycle. The random number generator can also include a switch for selecting, from the outputs of the logic gates, the random number to be output to the counter, making the number generated by the random number generator more difficult to predict.

[0011] Additionally, to prevent the random number generated by the random number generator from exceeding the maximum number of activations between update cycles, a number trimmer modifies the random number to a range from zero to a predetermined number (i.e., the maximum number of activations between update cycles). Since the memory columns adjacent to the activated memory column are more vulnerable to the column hammering effect, they will be protected in subsequent update cycles.

[0012] Generally, the amount of activation to trigger column hammering cannot be completed within two update cycles. For example, a memory element with 8192 columns can have approximately 170 activations between update cycles, and the amount of activation to trigger column hammering in the same column can be 10000 or more. Therefore, protecting additional vulnerable memory columns in each update cycle can eliminate the column hammering problem. In addition, the memory element can include a number trimmer circuit to determine whether the random number used to select one of the memory columns exceeds the maximum number of activations between update cycles (i.e., 170 in this case), and then reduce the random number to the range from 0 to 170, improving the security and performance of the memory element.

[0013] The technical features and advantages of the present disclosure have been outlined quite extensively above, so as to provide a better understanding of the following detailed description of the present disclosure. Other technical features and advantages constituting the subject matter of the claims of the present disclosure will be described below. Those skilled in the art to which the present disclosure pertains should understand that the concepts disclosed below and specific embodiments can be quite easily used as a basis for modifying or designing other structures or processes to achieve the same purposes as the present disclosure. Those skilled in the art to which the present disclosure pertains should also understand that such equivalent constructs cannot depart from the spirit and scope of the present disclosure as defined by the claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] A more complete understanding of the present disclosure can be obtained by reference to the detailed description as well as the claims. The present disclosure should also be understood as being associated with the element numbers of the drawings, and the element numbers of the drawings represent similar elements throughout the description.

[0015] Figure 1 is a schematic diagram illustrating memory elements of some embodiments of the present disclosure.

[0016] Figure 2 is a schematic diagram illustrating memory elements of some embodiments of the present disclosure.

[0017] Figure 2A is a schematic diagram illustrating memory elements of some embodiments of the present disclosure.

[0018] Figure 2B is a schematic diagram illustrating memory elements of some embodiments of the present disclosure.

[0019] Figure 3 is a schematic diagram illustrating the activation of word lines between update cycles along a time axis in some embodiments of the present disclosure.

[0020] Figure 3A is a schematic diagram illustrating the word line addresses accessed at each activation between update cycles along a time axis in some embodiments of the present disclosure.

[0021] Figure 3B is a schematic diagram illustrating the word line addresses accessed at each activation between update cycles along a time axis in some embodiments of the present disclosure.

[0022] Figure 3C is a schematic diagram illustrating the word line addresses accessed at each activation between update cycles along a time axis in some embodiments of the present disclosure.

[0023] Figure 4A is a schematic diagram illustrating the word line addresses accessed between update cycles along a time axis, as well as the updated word line addresses, column hammer target word line addresses, and initial reciprocal values in each update cycle, in some embodiments of the present disclosure.

[0024] Figure 4B It is a schematic diagram illustrating that some embodiments of the present disclosure display the word line addresses accessed between update cycles, as well as the updated word line addresses, column hammer target word line addresses, and initial reciprocal values in each update cycle along the time axis.

[0025] Figure 4C It is a schematic diagram illustrating that some embodiments of the present disclosure display the word line addresses accessed between update cycles, as well as the updated word line addresses, column hammer target word line addresses, and initial reciprocal values in each update cycle along the time axis.

[0026] Figure 4D It is a schematic diagram illustrating that some embodiments of the present disclosure display the word line addresses accessed between update cycles, as well as the updated word line addresses, column hammer target word line addresses, and initial reciprocal values in each update cycle along the time axis.

[0027] Figure 5 It is a schematic diagram illustrating that some embodiments of the present disclosure include a value adjuster in a memory element.

[0028] Figure 6 It is a flowchart illustrating a method for protecting a memory element according to some embodiments of the present disclosure.

[0029] Explanation of reference numerals:

[0030] 1: Memory element

[0031] 2: Memory element

[0032] 2A: Memory element

[0033] 2B: Memory element

[0034] 3A: Schematic diagram

[0035] 3B: Schematic diagram

[0036] 3C: Schematic diagram

[0037] 4A: Schematic diagram

[0038] 4B: Schematic diagram

[0039] 4C: Schematic diagram

[0040] 4D: Schematic diagram

[0041] 6: Protection method

[0042] 11: Memory cell

[0043] 12: Sense amplifier

[0044] 21: Memory cell

[0045] 22: Controller

[0046] 23: Random number generator

[0047] 23': Random number generator

[0048] 23": Random number generator

[0049] 23A: First number

[0050] 23B: Modified first number (second number)

[0051] 24: Counter

[0052] 25: Address register

[0053] 26: Value adjuster

[0054] 61: Step

[0055] 62: Step

[0056] 63: Step

[0057] 64: Step

[0058] 65: Step

[0059] 66: Step

[0060] 111: Memory column

[0061] 112: Memory column

[0062] 113: Memory column

[0063] 114: Memory column

[0064] 131: Column address decoder

[0065] 132: Row address decoder

[0066] 211: Possible target character line (first character line)

[0067] 212: Character line (second character line)

[0068] 213: Character line (second character line)

[0069] 214: Normal character line (third character line)

[0070] 231: Logic gate

[0071] 232: Logic gate

[0072] 233: Logic gate

[0073] 234: Logic gate

[0074] 235: Switch

[0075] 235': Switch

[0076] 235'': Switch

[0077] 261: Judgment Unit

[0078] 262: AND Gate

[0079] 2610: Judgment Result

[0080] 2611: First Part

[0081] 2612: Second Part

[0082] 2620: AND Output

[0083] act_1, act_2, act_3, …, act_N - 1, act_N: Start

[0084] Add CBR : Word Line

[0085] Add LRH : Accessed Word Line

[0086] Bit7, Bit6, Bit5, Bit4, Bit3, Bit2, Bit1, Bit0: Binary Sequence

[0087] Bit7', Bit6', Bit5', Bit4', Bit3', Bit2', Bit1', Bit0': Binary Sequence

[0088] CBR: First Update Cycle

[0089] CBR + 1: Second Update Cycle

[0090] CBR + 2: Third Update Cycle

[0091] CBR + 3: Fourth Update Cycle

[0092] CBR + 4: Fifth Update Cycle

[0093] CBR + 5: Sixth Update Cycle

[0094] CDN: Initial Reciprocal Value

[0095] CDN dec : Initial Reciprocal Value

[0096] CDN hex : Initial Reciprocal Value

[0097] L1: AND gate

[0098] L10: Output

[0099] L2: AND gate

[0100] L20: Output

[0101] L3: OR gate

[0102] L30: Output

[0103] L4: AND gate

[0104] L40: Output

[0105] L5: AND gate

[0106] L50: Output

[0107] L6: AND gate

[0108] L60: Output

[0109] L7: AND gate

[0110] L70: Output

[0111] L8: Logic gate (NOR gate)

[0112] R / W: Read / Write signal

[0113] RS: Update signal

[0114] S0: Select signal

[0115] S1: Select signal

[0116] S231: First output

[0117] S231 dec : First output

[0118] S231 hex : First output

[0119] S232: Second output

[0120] S232 dec : Second output

[0121] S232 hex : Second output

[0122] S233: Third output

[0123] S233 dec : Third output

[0124] S233 hex : Third output

[0125] S234: Fourth output

[0126] S234 dec : Fourth output

[0127] S234 hex : Fourth output

[0128] T act : Time period

[0129] T CBR : Time period

[0130] WL: Character line address

[0131] WL1: Character line address

[0132] WL2: Character line address

[0133] WL3: Character line address Detailed implementation manners

[0134] The following describes specific examples of components and configurations to simplify the embodiments of the present disclosure. Of course, these embodiments are only for illustration and are not intended to limit the scope of the present disclosure. For example, when it is described that the first component is formed on the second component, it may include embodiments where the first and second components are in direct contact, or it may include embodiments where additional components are formed between the first and second components such that the first and second components are not in direct contact. Additionally, the embodiments of the present disclosure may repeat reference numerals and / or letters in many examples. The purpose of these repetitions is to simplify and clarify, and unless otherwise specifically stated in the text, they do not themselves represent a specific relationship between various embodiments and / or the configurations discussed.

[0135] It should be understood that although terms such as first, second, and third may be used herein to describe various elements, components, regions, layers, or sections, these elements, components, regions, layers, or sections are not limited by these terms. On the contrary, these terms are only used to distinguish one element, component, region, layer, or section from another region, layer, or section. Therefore, without departing from the teachings of the inventive concept of progressiveness of the present invention, the first element, component, region, layer, or section discussed below may be referred to as the second element, component, region, layer, or section.

[0136] The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the present invention. As used herein, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that when the terms "comprises" and / or "comprising" are used in this specification, these terms specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups of the foregoing.

[0137] It should be understood that in the description of the present disclosure, the term "about" modifies the amounts of the components, compositions, or reactants of the present disclosure, meaning, for example, the variations in amounts that may occur through typical measurements for preparing concentrates or solutions and liquid handling procedures. Moreover, inadvertent errors in the measurement procedures, differences in the manufacture, source, or purity of the components used to make the compositions or implement the methods, etc. may result in variations. In one aspect, the term "about" means within 10% of the reported value. In another aspect, the term "about" means within 5% of the reported value. Further, in another aspect, the term "about" means within 10, 9, 8, 7, 6, 5, 4, 3, 2, or 1% of the reported value.

[0138] Figure 1 is a schematic diagram illustrating a memory element 1 of some embodiments of the present disclosure. The memory element 1 may include an array of a plurality of memory cells 11, a plurality of sense amplifiers 12, a column address decoder 131, and a row address decoder 132. In some embodiments, the memory element 1 may be a DRAM.

[0139] Please refer to Figure 1 , the array of memory cells 11 may include a plurality of columns and rows. Each row of memory cells may share a bit line or a pair of bit lines. Each column of memory cells may share a word line. In some embodiments, a single memory cell may include a capacitor and a transistor and is configured to store one bit of data therein. The charge state (charged or discharged) of the capacitor may determine whether the memory cell stores "1" or "0" as a binary value.

[0140] In some embodiments, a memory address applied to an array of memory cells 11 of a matrix can be represented as a column address and a row address, which are processed by a column address decoder 131 and a row address decoder 132. When the column address decoder 131 selects a specific column (e.g., memory column 114) for a read operation (this selection is also referred to as column activation), bits from all the memory cells in the specific column can be transferred to the sense amplifier 12. In some embodiments, one sense amplifier 12 is used for each row of memory cells to temporarily store data. In some embodiments, the row address decoder 132 can select the exact bit from one of the sense amplifiers 12. In some embodiments, the sense amplifier 12 can be configured to receive or transmit data in response to a read / write signal R / W. A write operation decodes the address in a similar manner, but can rewrite an entire column to change the value of a single bit.

[0141] Since data bits are stored in capacitors with a natural discharge rate, the state stored in the memory cells 11 may be lost over time, so all memory cells need to be rewritten periodically, which is a procedure called refresh, in order to preserve the information stored on the memory cells. Each memory refresh cycle can refresh one or more columns of memory cells, and all memory cells can be repeatedly refreshed in a continuous cycle. Memory refresh can be accomplished in various types. In some embodiments, memory refresh can be performed by signals of different modes, such as row address strobe (RAS) refresh, column address strobe before row address strobe (CAS-before-RAS) refresh (also referred to as CBR refresh for short), and hidden refresh.

[0142] To trigger a column hammer, the same memory column 111 can be activated at a high frequency and in a large quantity. When the activation frequency and quantity of the memory column 111 are large enough, the charge on the adjacent memory columns 112 and 113 that are not activated may leak, so the data / content stored therein may be lost.

[0143] This protection circuit provides a random number generator and a counter (for a detailed description, please refer to Figure 3 ) to randomly select and protect a possible memory column. The counter can be configured to count down from a random number generated by the random number generator. When the counter reaches zero, an address of the activated memory column (e.g., memory column 111) can be obtained. In other words, the memory column is selected from the memory columns activated between refresh cycles. The adjacent memory columns 112 and 113 near the activated memory column 111 are more likely to suffer from the column hammer effect, so they will be protected in subsequent refresh cycles. In some embodiments, the memory columns 112 and 113 and a planned refresh memory column 114 can be refreshed in subsequent refresh cycles.

[0144] Figure 2 is a schematic diagram illustrating the memory element 2 of some embodiments of the present disclosure. Please refer to Figure 2 , the memory element 2 may include an array of memory cells 21, a controller 22, a random number generator 23, a counter 24, an address register 25, and a value adjuster 26. In some embodiments, the memory element 2 may be a dynamic random access memory (DRAM).

[0145] In some embodiments, the array of memory cells 21 may include a plurality of word lines. In some embodiments, the array of memory cells 21 may include a possible target word line 211 being accessed, i.e., the column hammer target, two adjacent word lines 212 and 213 adjacent to the possible target word line 211, and a normal word line 214. The normal word line 214 may be located at any position in the array of memory cells 21. For example, the normal word line 214 may be an edge word line or a word line sandwiched between two word lines. In one embodiment, the normal word line 214 may be separated from the possible target word line 211. In another embodiment, the normal word line 214 may be adjacent to the possible target word line 211 (not shown in the figure).

[0146] The controller 22 may be configured to update at least one word line by providing an update signal RS during a first update cycle. In some embodiments, the update signal RS may be generated by the controller 22 itself based on a clock signal. In another embodiment, the controller 22 may be configured to update at least one word line in response to an update signal RS during a first update cycle. In such an embodiment, the controller 22 may receive the update signal RS from other elements (not shown in the figure). In some embodiments, the update signal RS may be a RAS update instruction or a CBR update instruction. The controller 22 may be configured to update one or more word lines during one update cycle. In some embodiments, the controller 22 may be configured to update one, two, three, four, or more word lines simultaneously. In some embodiments, the controller 22 may be configured to update the array of all memory cells 21 cycle by cycle. In some embodiments, the controller 22 may be configured to update the array of all memory cells 21 in a predetermined pattern (i.e., an update pattern).

[0147] The random number generator 23 can be configured to generate a first number 23A. The first number 23A can be a positive integer. In some embodiments, the first number 23A can be binary. The first number 23A can be represented by a binary sequence having more than 2 bits. For example, the first number 23A can be represented by an 8-bit binary sequence. That is, the first number 23A can be a value in the range of 0 to 255. In other embodiments, the first number 23A can be more or less than 8 bits.

[0148] The random number generator 23 can be configured to receive an address of a word line Add updated in the previous update cycle and an address of the accessed word line Add CBR i.e., a possible target column hammer word line in the previous update cycle. In some embodiments, the random number generator 23 can be configured to generate the first number 23A based on the address of the word line Add LRH (e.g., word line 214) and the address of the accessed word line Add CBR (e.g., word line 211). LRH (e.g., word line 211).

[0149] In some embodiments, the address of the word line Add CBR and the address of the accessed word line Add LRH can both be represented by a 4-bit hexadecimal sequence. The address of the word line represented by a 4-bit hexadecimal sequence can be converted into a 16-bit binary sequence.

[0150] Please refer to Figure 2 , the random number generator 23 can include one or more logic gates 231 and 232 and a switch 235. In some embodiments, the logic gates 231 and 232 can include different types of logic gates. The logic gates 231 and 232 can include OR gates, AND gates, NOR gates, NAND gates, XOR gates, XNOR gates, etc. For example, the logic gate 231 can be an XOR gate and the logic gate 232 can be an AND gate.

[0151] The logic gate 231 can have a first input terminal receiving the address of the word line Add CBR , a second input terminal receiving the address of the accessed word line Add LRH , and an output terminal outputting a first output S231. The logic gate 231 can be configured to generate the first output S231 based on the address of the word line Add CBR and the address of the accessed word line Add LRH . In some embodiments, the logic gate 231 can be configured to generate the first output S231 based on a part of the address of the word line Add CBR and the address of the accessed word line Add LRHA part of the address to generate a first output S231.

[0152] The logic gate 232 can receive the word line Add CBR A first input terminal of the address, receive the accessed word line Add LRH A second input terminal of the address, and an output terminal for outputting a second output S232. The logic gate 232 can be configured to generate the second output S232 according to the address of the word line Add CBR The address and the accessed word line Add LRH The address to generate the second output S232. In some embodiments, the logic gate 232 can be configured to generate the second output S232 according to a part of the address of the word line Add CBR And a part of the address of the accessed word line Add LRH The part of the address to generate the second output S232.

[0153] In some embodiments, the first input terminal of the logic gate 231 can be connected to the first input terminal of the logic gate 232 to receive the address of the word line Add CBR The address. The second input terminal of the logic gate 231 can be connected to the second input terminal of the logic gate 232 to receive the address of the accessed word line Add LRH The address.

[0154] Although the logic gates 231 and 232 receive the same inputs, namely the address of the word line Add CBR The address and the accessed word line Add LRH The address, but since the logic gates 231 and 232 can include different types of logic gates with different calculations, the first output S231 and the second output S232 can be different.

[0155] In some embodiments, when the address of the word line Add CBR Is represented by a 4-bit hexadecimal sequence, the part of the address of the word line Add input to the random number generator 23 CBR Can be 2 bits, that is, half of the total bit length. In other embodiments, this part of the address of the word line Add CBR Can be the last 2 bits, regardless of the total bit length. In some embodiments, the hexadecimal address of the word line Add CBR Can be converted to binary. In some embodiments, the 2-bit hexadecimal of the address of the word line Add CBR Can be converted to 8-bit binary.

[0156] In some embodiments, when the address of the accessed word line Add LRH Is represented by a 4-bit hexadecimal sequence, the accessed word line Add LRHThe portion of the address input to the random number generator 23 can be 2 bits, i.e., the total bit length. In other embodiments, the portion of the address of the accessed word line Add LRH can be the last 2 bits, regardless of the total bit length. In some embodiments, the accessed word line Add LRH The hexadecimal address can be converted to binary. In some embodiments, accessing the 2 hexadecimal bits of the address of the bit line Add LRH can be converted to 8 binary bits.

[0157] The portion of the word line Add input to the random number generator 23 (such as logic gates 231 and 232) CBR and the portion of the accessed word line Add LRH can have the same bit length. In some embodiments, the bits of the word line Add input to the random number generator 23 CBR and the bits of the accessed word line Add LRH can be determined according to the size of the memory array.

[0158] In some embodiments, the switch 235 can be electrically coupled to the logic gates 231 and 232. The switch 235 can be connected to the output of the logic gate 231. The switch 235 can be connected to the output of the logic gate 232. That is, the switch 235 can be configured to receive the first output S231 and the second output S232. In some embodiments, the switch 235 can be configured to select one of the first output S231 and the second output S232 as the first number 23A, i.e., the output of the random number generator 23. In some embodiments, the first number 23A is selected from the first output S231 and the second output S232, so the unpredictability can be increased.

[0159] In some embodiments, the switch 235 is configured to select between the first output S231 and the second output S232 in response to a selection signal S0. In some embodiments, the switch 235 can be a multiplexer (MUX). For example, the switch 235 can be a 2-to-1 MUX. In other embodiments, the switch 235 can be other suitable components.

[0160] In some embodiments, in each update cycle, switch 235 can be configured to sequentially select first output S231 and second output S232 as first number 23A in response to selection signal S0. In another embodiment, in each update cycle, switch 235 can be configured to randomly select first output S231 and second output S232 as first number 23A in response to selection signal S0. In some embodiments, selection signal S0 can be generated by controller 22 based on a clock signal. In another embodiment, switch 235 can receive selection signal S0 from other elements (not shown in the figure).

[0161] In some embodiments, random number generator 23 can be coupled to counter 24. Random number generator 23 can be connected to counter 24 through value adjuster 26. In another embodiment, random number generator 23 can be connected to counter 24 bypassing value adjuster 26 (not shown in the figure).

[0162] Random number generator 23 can be configured to generate a random number (i.e., first number 23A) in response to the address of word line Add CBR and the address of the accessed word line Add LRH . Although the word line Add CBR can be predetermined according to the update mode, the accessed word line Add LRH can be randomly selected from the memory array. Therefore, the first number 23A may be more difficult to predict. Thus, the security of memory element 2 can be improved.

[0163] Value adjuster 26 can be connected to random number generator 23 and is configured to receive first number 23A. Value adjuster 26 can be a circuit that reduces the first number 23A to less than a critical value. In some embodiments, value adjuster 26 can be configured to generate a modified first number 23B (or a second number 23B) according to the first number 23A. In some embodiments, when the first quantity 23A is greater than a first predetermined number, value adjuster 26 can modify the first number 23A to the modified first number 23B. In some embodiments, the first predetermined number is the maximum number of accesses between update cycles (for a detailed description, reference can be made to Figure 3 ). After modification, the modified first number 23B is less than the first predetermined number. The modified first number 23B can be less than the first number 23A.

[0164] Before discussing Figure 2A and 2B the memory elements 2A and 2B shown, the operations performed by memory element 2 during the update cycle will be described in detail according to Figure 3 , Figure 3A , Figure 3B and Figure 3C .

[0165] Figure 3 is a schematic diagram illustrating the activation of a character line between update cycles along a time axis in some embodiments of the present disclosure.

[0166] Please refer to Figure 3 , along the time axis (i.e., the x-axis), a time period T CBR is located between a first update cycle CBR and a second update cycle CBR+1. In some embodiments, the second update cycle CBR+1 immediately follows the first update cycle CBR. In some embodiments, each of the first update cycle CBR and the second update cycle CBR+1 may include a period for an update operation and an idle period. The idle period described herein refers to the waiting time from the start of the update cycle CBR to the start of the update cycle CBR+1. Therefore, the time period T CBR can be from the start point of the first update cycle CBR to the start point of the second update cycle CBR+1.

[0167] In some embodiments, N activations (act_1, act_2, act_3,..., act_N-1, act_N) occur between the first update cycle CBR and the second update cycle CBR+1. Each activation act_1, act_2, act_3, act_N-1, and act_N represents an access to a character line. The time period T act is between two activations. For example, the time period T act can be between activation act_1 and act_2. In some embodiments, the time period T act can be the minimum necessary time to access a character line (such as the first activation act_1).

[0168] To clearly illustrate the present disclosure, a memory array with 8k character lines is taken as an example. The memory array may include 8192 character lines. The addresses of the character lines may be represented by a hexadecimal sequence, for example, using 4 bits. In some embodiments, the time to update all the character lines (i.e., 8192 character lines) may be 64 ms. At this time, the time period T required to update one character line CBR can be calculated as 64 ms / 8192, so the time period T CBR is 7.8125 μs. In other words, for a total of 8k character lines, the time period T from the start point of the first update cycle to the start point of the second update cycle CBR can be 7.8125 μs. Assuming the time period T act is 45.75 ns, the maximum number of accesses N between update cycles max can be calculated according to the formula . Therefore, the maximum number of accesses N maxIt can be 7.8125 μs / 45.75 ns = 170.765 ≈ 170, that is, Figure 3 the number N in Figure 3 is 170. In this embodiment, 170 word lines can be accessed between update cycles. Accordingly, the first number 23A received by the counter 24 can be modulated to be lower than a predetermined number (for example, 170 in this embodiment).

[0169] In some embodiments, the first number 23A can be less than a predetermined number, which is related to the time period T for accessing the word lines act and the time period T between the first update cycle CBR and the second update cycle CBR + 1. CBR In some embodiments, the counter 24 can be configured to reset the initial value when the first number 23A is greater than the predetermined number. For example, the initial value of the counter 24 can be reset to zero or a constant less than the predetermined number. Thus, the counter 24 can start counting down from an initial value within the range from 0 to the predetermined number (i.e., the maximum number of accesses between update cycles), and when it decrements to zero, it can be selected to protect the word lines during the subsequent update cycle.

[0170] Please refer again to Figure 2 , the modified first number 23B can be represented in the same form as the first number 23A. In some embodiments, both the first number and the modified number can be binary. For example, if the first number 23A is represented by a binary sequence with 8 bits, then the modified first number 23B is also represented by a binary sequence with 8 bits. In some embodiments, the first number 23A can be represented by a binary sequence having Bit7, Bit6, Bit5, Bit4, Bit3, Bit2, Bit1, and Bit0. The modified first number 23B can be represented by a binary sequence having Bit7', Bit6', Bit5', Bit4', Bit3', Bit2', Bit1', and Bit0'.

[0171] The difference between the first number 23A and the modified first number 23B can be one bit of the binary sequence. For example, a most significant bit (msb) of the first number 23A can be different from the most significant bit of the modified first number 23B. That is, Bit7' of the modified first number 23B is different from Bit7 of the first number 23A. In some embodiments, Bit6' to Bit0' of the modified first number 23B can be the same as Bit6 to Bit0 of the first number 23A. In another embodiment, the modified first number 23B can be reset to zero by the value adjuster 26. Thus, Bit7' to Bit0' of the modified first number 23B are logic "0".

[0172] Conversely, when the first number 23A is less than the first predetermined number, the value adjuster 26 does not take any action on the first number 23A. In this case, the modified first number 23B will be the same as the original first number 23A.

[0173] The counter 24 can be electrically coupled to the random number generator 23 and the value adjuster 26. In some embodiments, the counter 24 can be electrically decoupled to the random number generator 23 through the value adjuster 26. The counter 24 can be configured to receive the modified first number 23B as an initial value of the counter 24. That is, the counter 24 can start counting down from this initial value (i.e., the modified first number 23B). In one embodiment, when the first number 23A is less than the first predetermined number, the modified first number 23B is the same as the first number 23A, and the counter 24 decrements from the modified first number 23B, i.e., the first number 23A. In another embodiment, when the first number 23A is greater than the first predetermined number, the first number 23A is modified to the modified first number 23B that is less than the first predetermined number, and the counter 24 decrements from the modified first number 23B that is different from the first number 23A.

[0174] In some embodiments, the counter 24 is configured to be turned on in response to an update signal RS received from the controller 22. In other words, the counter 24 can be configured to start counting down in response to the update signal RS. The counter 24 can be configured to decrement from an initial value, which is the first number 23A or the modified first number 23B.

[0175] In some embodiments, the counter 24 can be configured to decrement in response to an access signal indicating an access to one of the word lines.

[0176] The address register 25 can be electrically coupled to the counter 24. The address register 25 can be configured to obtain the address of the first word line 211 (or possibly the target word line 211) that is valid when the counter 24 decrements to zero, and store the address.

[0177] Figure 3A is schematic Figure 3A illustrating the word line addresses accessed at each startup between the update cycles CBR and CBR + 1 of some embodiments of the present disclosure along the time axis.

[0178] Please refer to Figure 3A, access the word line address WL1 each time act_1, act_2, act_3, act_4, ... and act_N are started. In this case, regardless of the initial value of the counter 24, the address register 25 stores the word line address WL1 that is accessed the most times. In other words, the word line address WL1 is most likely to be the target of a malicious operator. Therefore, selecting a word line adjacent to the word line address WL1 to be protected can prevent column hammering.

[0179] Figure 3B is schematic Figure 3B , illustrating the word line addresses accessed at each start between update cycles CBR and CBR+1 along the time axis in some embodiments of the present disclosure.

[0180] Please refer to Figure 3B , access the word line address WL1 when act_1 is started. Access the word line address WL2 at the start of act_2. Access the word line address WL1 at the start of act_3. Access the word line address WL2 at the start of act_4. Access the word line address WL2 when act_N is started. That is, only the word line addresses WL1 and WL2 are accessed. In this case, regardless of the initial value of the counter 24, the address register 25 stores the word line address WL1 or WL2 that is accessed the most times. In some embodiments, the probability of the word line addresses WL1 and WL2 being attacked is 50% each. In other words, the word line addresses WL1 and WL2 are most likely to be the targets of an attacker. Therefore, selecting a word line adjacent to the word line address WL1 or WL2 for protection can prevent column hammering.

[0181] Figure 3C is schematic Figure 3C , illustrating the word line addresses accessed at each start between update cycles CBR and CBR+1 along the time axis in some embodiments of the present disclosure.

[0182] Please refer to Figure 3C, access the character line address WL1 when act_1 is started. Access the character line address WL2 at the start of act_2. Access the character line address WL3 at the start of act_3. Access the character line address WL1 at the start of act_4. Access the character line address WL2 when act_N-1 is started. Access the character line address WL3 at the start of act_N. In some embodiments, the character line addresses WL1, WL2, and WL3 are accessed repeatedly in sequence. That is, only the character line addresses WL1, WL2, and WL3 are accessed between update cycles. In this case, the address register 25 stores one of the character line addresses WL1, WL2, and WL3. In some embodiments, the probability that the character line addresses WL1, WL2, and WL3 are attacked can be approximately 33.33%. In other words, the character line addresses WL1, WL2, and WL3 are most likely to be targeted by malicious operators. Therefore, selecting a character line adjacent to the character line address WL1, WL2, or WL3 for protection can prevent column hammering.

[0183] Please refer to Figures 3A to 3C , the address of the character line to be protected can be randomly selected from those character lines that are valid during two update cycles. The character line is selected from the character lines started between update cycles. In this case, the selection pool includes the character lines started between update cycles.

[0184] Please refer back to Figure 2 , the controller 22 can be configured to access the address register 25 during a second update cycle to obtain the address of the first character line and protect the second character line 212 / 213 (i.e., the adjacent character line 212 or 213). To protect the second character line 212 / 213, the controller can be configured to update the second character line 212 / 213 during the second update cycle in response to the update signal RS. In some embodiments, the second update cycle is after the first update cycle. For example, the second update cycle can be a subsequent update cycle of the first update cycle. In some embodiments, the second character line 212 / 213 is adjacent to the first character line 211.

[0185] The controller 22 can be configured to update one or more character lines during an update cycle. In some embodiments, the controller 22 can be configured to update one, two, three, four, or more character lines simultaneously. The controller 22 can be configured to update the adjacent character lines 212 and 213 during the same update cycle. In some embodiments, in addition to the second character line 212 / 213, the controller 22 can also be configured to update a third character line 214 during the second update cycle in response to the update signal RS, where the address of the third character line 214 is separated from the address of the first character line 211.

[0186] In some embodiments, the controller 22 may be configured to update one word line adjacent to the possible target word line 211 and another word line separated from the possible target word line 211. For example, the word line 212 and the word line 214 may be updated during the second update period. In some embodiments, in one update period, the controller 22 may be configured to update one normal word line (e.g., the word line 214) and one high-risk word line (e.g., the word lines 212 and 213) according to a predetermined update pattern determined by the random number generator 23 and the counter 24. That is, in one update period, at least one normal updated word line and at least one word line having a high column hammer effect risk may be updated simultaneously.

[0187] In the present disclosure, when the counter 24 decrements to zero, the address of the activated first word line 211 (or the possible target word line 211) can be obtained. In this case, the address of the word line to be protected can be randomly selected from those word lines that are valid during two update periods. Additionally, the numerical adjuster 26 modifies the first number 23A to a range from zero to a first predetermined number to prevent the first number 23A from exceeding the maximum activation times between update periods.

[0188] Figure 2A is a schematic diagram illustrating the memory element 2A of some embodiments of the present disclosure. Figure 2A The memory element 2A of Figure 2 is similar to the memory element 2 of Figure 2A except that the memory element 2A of

[0189] Please refer to Figure 2A , the random number generator 23' may include logic gates 231, 232, and 233 and a switch 235'. In some embodiments, the logic gates 231, 232, and 233 may include different types of logic gates. The logic gates 231, 232, and 233 may include OR gates, AND gates, NOR gates, NAND gates, XOR gates, XNOR gates, etc. For example, the logic gate 231 may be an XOR gate. The logic gate 232 may be an AND gate. The logic gate 233 may be an OR gate.

[0190] Figure 2A The arrangement of the logic gates 231 and 232 in Figure 2 is similar to that in CBR In some embodiments, the logic gate 233 may have a first input terminal for receiving the address of the word line Add LRHa second input terminal of the address, and an output terminal that outputs a third output S233. The logic gate 233 may be configured to generate the third output S233 according to the address of the word line Add CBR the address and the accessed word line Add LRH the address to generate the third output S233. In some embodiments, the logic gate 233 may be configured to generate the third output S233 according to a part of the address of the word line Add CBR and a part of the address of the accessed word line Add LRH the address. In some embodiments, the operation of the logic gate 233 may be similar to the operation of the logic gate 231 or 232.

[0191] In some embodiments, the first input terminal of the logic gate 231, the first input terminal of the logic gate 232, and the first input terminal of the logic gate 233 may be connected to receive the address of the word line Add CBR The second input terminals of the logic gate 231, the logic gate 232, and the logic gate 233 may be connected to receive the address of the accessed word line Add LRH the address.

[0192] Although the logic gates 231, 232, and 233 receive the same inputs, i.e., the address of the word line Add CBR and the address of the accessed word line Add LRH the address, the first output S231, the second output S232, and the third output S233 may be different because different types of logic gates have different calculations.

[0193] In some embodiments, the switch 235' may be electrically coupled to the logic gates 231, 232, and 233. The switch 235' may be connected to the output terminals of the logic gates 231, 232, and 233. That is, the switch 235' may be configured to receive the first output S231, the second output S232, and the third output S233. In some embodiments, the switch 235' may be configured to select one of the first output S231, the second output S232, and the third output S233 as the first number 23A, i.e., the output of the random number generator 23. In some embodiments, the first number 23A is selected from the first output S231, the second output S232, and the third output S233, thus increasing the unpredictability.

[0194] In some embodiments, switch 235' is configured to select among a first output S231, a second output S232, and a third output S233 in response to a selection signal S0 and S1. In some embodiments, switch 235' may be a multiplexer (MUX). For example, switch 235' may be a 3 - to - 1 MUX or a 4 - to - 1 MUX. In other embodiments, switch 235' may be other suitable components.

[0195] In some embodiments, in each update cycle, switch 235' may be configured to sequentially select the first output S231, the second output S232, and the third output S233 as a first number 23A in response to the selection signals S0 and S1. In another embodiment, in each update cycle, switch 235' may be configured to randomly select the first output S231, the second output S232, and the third output S233 as the first number 23A in response to the selection signals S0 and S1. In some embodiments, the selection signals S0 and S1 may be generated by controller 22 based on a clock signal. In another embodiment, switch 235' may receive the selection signals S0 and S1 from other components (not shown in the figure).

[0196] Figure 2B is a schematic diagram illustrating a memory element 2B according to some embodiments of the present disclosure. Figure 2B The memory element 2B is similar to Figure 2A the memory element 2A, except that Figure 2B the memory element 2B includes a random number generator 23”, and the random number generator 23” includes four logic gates 231, 232, 233, and 234.

[0197] Please refer to Figure 2B , the random number generator 23” may include logic gates 231, 232, 233, and 234 and a switch 235”. In some embodiments, the logic gates 231, 232, 233, and 234 may include different types of logic gates. The logic gates 231, 232, 233, and 234 may include OR gates, AND gates, NOR gates, NAND gates, XOR gates, XNOR gates, etc. For example, logic gate 231 may be an XOR gate. Logic gate 232 may be an AND gate. Logic gate 233 may be an OR gate. Logic gate 234 may be a NOR gate.

[0198] Figure 2B The arrangement of the logic gates 231, 232, and 233 in Figure 2A is similar to that in CBR The first input terminal of logic gate 234 may receive the address of the word line Add LRHa second input terminal of the address, and an output terminal for outputting a fourth output S234. The logic gate 234 can be configured to generate the fourth output S234 according to the address of the word line Add CBR the address and the accessed word line Add LRH the address to generate the fourth output S234. In some embodiments, the logic gate 234 can be configured to generate the fourth output S234 according to a part of the address of the word line Add CBR and a part of the address of the accessed word line Add LRH the address. In some embodiments, the operation of the logic gate 234 can be similar to the operations of the logic gates 231, 232, or 233.

[0199] In some embodiments, the first input terminal of the logic gate 231, the first input terminal of the logic gate 232, the first input terminal of the logic gate 233, and the first input terminal of the logic gate 234 can be connected to receive the address of the word line Add CBR The second input terminals of the logic gate 231, the logic gate 232, the logic gate 233, and the logic gate 234 can be connected to receive the address of the accessed word line Add LRH the address.

[0200] Although the logic gates 231, 232, 233, and 234 receive the same inputs, i.e., the address of the word line Add CBR the address and the accessed word line Add LRH the address, the first output S231, the second output S232, the third output S233, and the fourth output S234 can be different due to different calculations of different types of logic gates.

[0201] In some embodiments, the switch 235” can be electrically coupled to the logic gates 231, 232, 233, and 234. The switch 235” can be connected to the output terminals of the logic gates 231, 232, 233, and 234. That is, the switch 235” can be configured to receive the first output S231, the second output S232, the third output S233, and the fourth output S234. In some embodiments, the switch 235” can be configured to select one of the first output S231, the second output S232, the third output S233, and the fourth output S234 as the first number 23A, i.e., the output of the random number generator 23. In some embodiments, the first number 23A is selected from the first output S231, the second output S232, the third output S233, and the fourth output S234, increasing its unpredictability.

[0202] In some embodiments, switch "235" is configured to select among a first output S231, a second output S232, a third output S233, and a fourth output S234 in response to selection signals S0 and S1. In some embodiments, switch "235" can be a multiplexer (MUX). For example, switch "235" can be a 4-to-1 MUX. In other embodiments, switch "235" can be other suitable components.

[0203] In some embodiments, in each update cycle, switch "235" can be configured to sequentially select the first output S231, the second output S232, the third output S233, and the fourth output S234 as a first number 23A in response to selection signals S0 and S1. In another embodiment, in each update cycle, switch "235" can be configured to randomly select the first output S231, the second output S232, the third output S233, and the fourth output S234 as a first number 23A in response to selection signals S0 and S1. In some embodiments, selection signals S0 and S1 can be generated by controller 22 based on a clock signal. In another embodiment, switch "235" can receive selection signals S0 and S1 from other components (not shown in the figures).

[0204] According to some embodiments of the present disclosure, Figures 4A to 4D Illustrative Figure 2B A case where switch "235" of the random number generator "23" of the memory element 2B in the example sequentially selects the first output S231, the second output S232, the third output S233, and the fourth output S234 in each update cycle.

[0205] Figure 4A Is schematic Figure 4A Illustrating some embodiments of the present disclosure showing the word line addresses accessed between update cycles CBR and CBR + 1 along the time axis, and the updated word line address Add in each update cycle CBR 、Column hammer target word line address Add LRH And the initial reciprocal value CDN.

[0206] Please refer to Figure 4A At the start of act_1, the word line address WL accessed is 1235. At the start of act_2, the word line address WL accessed is 0021. At the start of act_3, the word line address WL accessed is 1235. At the start of act_59, the word line address WL accessed is 1235. At the start of act_60, the word line address WL accessed is 0021. At the start of act_N - 1, the word line address WL accessed is 1235. At the start of act_N, the word line address WL accessed is 0021. That is, only two word line addresses 1235 and 0021 are accessed. In some embodiments, Figure 4AThe character line address in it is represented by a hexadecimal sequence with 4 bits. In other words, the character line address WL with hexadecimal 1235 can be equivalent to decimal 4661 and equivalent to binary 0001001000110101. The character line address WL with hexadecimal 0021 can be equivalent to decimal 33 and binary 0000000000100001.

[0207] In the update cycle CBR, the updated character line address AddCBR can be, for example, 1ABC. When the update cycle CBR is the initial update cycle, there is no previous update cycle, so the possible target column hammer character lines are at address Add LRH (in the previous update cycle) can be 0000. The character line address WL with hexadecimal 1ABC is equivalent to decimal 6844 and equivalent to 0001101010111100. As Figure 2B discussed, the random number generator 23” can be configured to respond to the last 2 bits of the hexadecimal updated character line address Add CBR and the column hammer target character line address Add LRH to generate the first number 23A.

[0208] In response to the last 2 bits of the updated character line address Add CBR being BC and the last 2 bits of the column hammer target character line address Add LRH being 00, according to the operation of the logic gate 231, the first output S231 hex can be BC (e.g., XOR). In some embodiments, the first output S231 hex = BC can be equal to the first output S231 dec = 188.

[0209] In response to the last 2 bits of the updated character line address Add CBR being BC and the last 2 bits of the column hammer target character line address Add LRH being 00, according to the operation of the logic gate 232, the second output S232 hex can be 00 (e.g., AND). In some embodiments, the second output S232 hex = 00 can be equivalent to the second output S232 dec = 0.

[0210] In response to the last 2 bits of the updated character line address Add CBR being BC and the last 2 bits of the column hammer target character line address Add LRH being 00, according to the operation of the logic gate 233, the third output S233 hex can be BC (e.g., OR). In some embodiments, the third output S233hex = BC can be equal to the third output S233 dec = 188.

[0211] In response to updating the character line address Add CBR The last 2 bits of are BC and the column hammer target character line address Add LRH The last 2 bits of are 00, according to the operation of logic gate 234, the fourth output S234 hex can be 43 (e.g., NOR). In some embodiments, the fourth output S234 hex = 43 can be equal to the fourth output S234 dec = 67.

[0212] For the first update cycle CBR, switch 235” can select the first output S231 as the first digit 23A. The first number 23A can be hexadecimal BC (decimal 188), thus exceeding the first predetermined number (e.g., decimal 171). After the operation of the numerical adjuster 26, the first number 23A can be reset to zero to become the modified first number 23B input to the counter 24. Thus, the initial countdown value CDN hex (the initial value of counter 24), i.e., the modified first digit 23B, can be hexadecimal 3C. In some embodiments, the initial countdown value CDN hex = 3C can be equal to the initial countdown value CDN dec = 60. In this case, the counter 24 can start counting down from 60, and the address register 25 can be configured to obtain the character line address accessed at the start act_60 between the update cycles CBR and CBR+1, i.e., WL of 0021. Accordingly, in the subsequent update cycle CBR+1, the column hammer target character line address Add LRH will be 0021. That is, the adjacent character line address that can be protected as 0021 in the update cycle CBR+1 (e.g., the character line address of 0020 or 0022).

[0213] In the update cycle CBR+1, the updated character line address Add CBR can be 1ABD, and the column hammer target character line address Add LRH can be 0021. The character line address WL of hexadecimal 1ABD is equivalent to decimal 6845, equivalent to 0001101010111101.

[0214] In response to updating the character line address Add CBR The last 2 bits of are BD and the column hammer target character line address Add LRH The last 2 bits of are 21, according to the operation of logic gate 231, the first output S231hex can be 9C (e.g., XOR). In some embodiments, the first output S231 hex = 9C can be equal to the first output S231 dec = 156.

[0215] In response to updating the character line address Add CBR whose last 2 bits are BD and the column hammer target character line address Add LRH whose last 2 bits are 21, according to the operation of logic gate 232, the second output S232 hex can be 21 (e.g., AND). In some embodiments, the second output S232 hex = 21 can be equal to the second output S232 dec = 33.

[0216] In response to updating the character line address Add CBR whose last 2 bits are BD and the column hammer target character line address Add LRH whose last 2 bits are 21, according to the operation of logic gate 233, the third output S233 hex can be BD (e.g., OR). In some embodiments, the third output S233 hex = BD can be equal to the third output S233 dec = 189.

[0217] In response to updating the character line address Add CBR whose last 2 bits are BD and the column hammer target character line address Add LRH whose last 2 bits are 21, according to the operation of logic gate 234, the fourth output S234 hex can be 42 (e.g., NOR). In some embodiments, the fourth output S234 hex = 42 can be equal to the fourth output S234 dec = 66.

[0218] For the second update cycle CBR + 1, switch 235” can select the second output S232 as the first digit 23A. The first digit 23A can be hexadecimal 21 (decimal 33), and thus less than the first predetermined number (e.g., decimal 171). Without triggering the operation of the value adjuster 26, the first digit 23A can be the same as the modified first digit 23B to be input to the counter 24. Therefore, the initial countdown value CDN hex (the initial value of counter 24), i.e., the modified first digit 23B, can be hexadecimal 21. In some embodiments, the initial countdown value CDN hex = 21 can be equal to the initial countdown value CDN dec= 33. In this case, the counter 24 can count down from 33, and the address register 25 can be configured to obtain the character line address accessed at the start act_33 between the update cycles CBR+1 and CBR+2 (please refer to Figure 4B ).

[0219] Figure 4B is schematic Figure 4B , illustrating some embodiments of the present disclosure showing the character line addresses accessed between the update cycles CBR+1 and CBR+2 along the time axis, as well as the updated character line address Add CBR in each update cycle, the column hammer target character line address Add LRH and the initial countdown value CDN.

[0220] Please refer to Figure 4B , the character line address WL accessed at the start act_1 is 1235. The character line address WL accessed at the start act_2 is 0021. The character line address WL accessed at the start act_3 is 1235. The character line address WL accessed at the start act_33 is 1265. The character line address WL accessed at the start act_34 is 0021. The character line address WL accessed at the start act_N-1 is 1235. The character line address WL accessed at the start act_N is 0021. That is, only two character line addresses 1235 and 0021 are accessed.

[0221] In the update cycle CBR+1, the updated character line address Add CBR can be 1ABD, and the column hammer target character line address Add LRH can be 0021. As Figure 4A shown, in response to the last 2 bits of the updated character line address Add CBR being BD, and the last 2 bits of the column hammer target character line address Add LRH being 21, the initial countdown value CDN hex in the update cycle CBR+1 can be hexadecimal 21. In some embodiments, the initial countdown value CDN hex = 21 can be equal to the initial countdown value CDN dec = 33. In this case, the counter 24 can start counting down from 33, and the address register 25 can be configured to obtain the character line address accessed at the start act_33 between the update cycles CBR+1 and CBR+2, that is, WL is 1235. Therefore, in the next update cycle CBR+2, the column hammer target character line address Add LRHIt will be 1235. That is, the adjacent character line addresses that are 1265 (for example, the character line addresses that are 1234 or 1236) can be protected in the update cycle CBR + 2.

[0222] In the update cycle CBR + 2, update the character line address Add CBR can be 1ABE, and the column hammer target character line address Add LRH can be 1235. The character line address WL of hexadecimal 1ABE can be equivalent to decimal 6846 and equivalent to 0001101010111110.

[0223] In response to the update character line address Add CBR whose last 2 bits are BE and the column hammer target character line address Add LRH whose last 2 bits are 35, according to the operation of the logic gate 231, the first output S231 hex can be 8B (for example, XOR). In some embodiments, the first output S231 hex = 8B can be equal to the first output S231 dec = 139.

[0224] In response to the update character line address Add CBR whose last 2 bits are BE and the column hammer target character line address Add LRH whose last 2 bits are 35, according to the operation of the logic gate 232, the second output S232hex can be 34 (for example, AND). In some embodiments, the second output S232 hex = 34 can be equal to the second output S232 dec = 52.

[0225] In response to the update character line address Add CBR whose last 2 bits are BE and the column hammer target character line address Add LRH whose last 2 bits are 35, according to the operation of the logic gate 233, the third output S233 hex can be BF (for example, OR). In some embodiments, the third output S233 hex = BF can be equal to the third output S233 dec = 191.

[0226] In response to the update character line address Add CBR whose last 2 bits are BE and the column hammer target character line address Add LRH whose last 2 bits are 35, according to the operation of the logic gate 234, the fourth output S234hex can be 40 (for example, NOR). In some embodiments, the fourth output S234 hex= 40 can be equal to the fourth output S234 dec = 64.

[0227] For the third update period CBR + 2, switch 235” can select the third output S233 as the first number 23A. The first number 23A can be BF in hexadecimal (191 in decimal), thus exceeding the first predetermined number (e.g., 171 in decimal). After the operation of the value adjuster 26, the first number 23A can be reset to zero to become the modified first digit 23B input to the counter 24. Thus, the initial countdown value CDN hex (the initial value of counter 24), that is, the modified first number 23B, can be 3F in hexadecimal. In some embodiments, the initial countdown value CDN hex = 3F can be equal to the initial countdown value CDN dec = 63. In this case, the counter 24 can start counting down from 63, and the address register 25 can be configured to obtain the character line address accessed at the start act_63 between the update periods CBR + 2 and CBR + 3 (please refer to Figure 4C ).

[0228] Figure 4C is schematic Figure 4C , illustrating some embodiments of the present disclosure showing the character line addresses accessed between the update periods CBR + 2 and CBR + 3 along the time axis, as well as the updated character line addresses Add CBR in each update period, the column hammer target character line address Add LRH and the initial countdown value CDN.

[0229] Please refer to Figure 4C , the character line address WL accessed at the start act_1 is 1235. The character line address WL accessed at the start act_2 is 0021. The character line address WL accessed at the start act_3 is 1235. The character line address WL accessed at the start act_63 is 1235. The character line address WL accessed at the start act_64 is 0021. The character line address WL accessed at the start act_N - 1 is 1235. The character line address WL accessed at the start act_N is 0021. That is, only two character line addresses, 1235 and 0021, are accessed.

[0230] In the update period CBR + 2, the updated character line address Add CBR can be 1ABE, and the column hammer target character line address Add LRH can be 1235. As Figure 4B shown, in response to the last 2 bits of the updated character line address Add CBR being BE, the column hammer target character line address AddLRH The last two bits are 35, and the initial countdown value CDN in the update period CBR+2 hex can be 3F in hexadecimal. In some embodiments, the initial countdown value CDN hex = 3F can be equal to the initial countdown value CDN dec = 63. In this case, the counter 24 can start counting down from 63, and the address register 25 can be configured to obtain the word line address accessed at the start act_63 between the update periods CBR+2 and CBR+3, which is the WL of 1235. Accordingly, in the subsequent update period CBR+3, the column hammer target word line address Add LRH will also be 1235. That is, the adjacent word line addresses (such as word line address 1234 or 1236) that can be protected as 1235 in the update period CBR+3.

[0231] In the update period CBR+3, the updated word line address Add CBR can be 1ABF, and the column hammer target word line address Add LRH can be 1235. The word line address WL of hexadecimal 1ABF can be equivalent to decimal 6847 and equivalent to 0001101010111111.

[0232] In response to the last two bits of the updated word line address Add CBR being BF and the last two bits of the column hammer target word line address Add LRH being 35, according to the operation of the logic gate 231, the first output S231 hex can be 8A (e.g., XOR). In some embodiments, the first output S231 hex = 8A can be equal to the first output S231 dec = 138.

[0233] In response to the last two bits of the updated word line address Add CBR being BF and the last two bits of the column hammer target word line address Add LRH being 35, according to the operation of the logic gate 232, the second output S232 hex can be 35 (e.g., AND). In some embodiments, the second output S232 hex = 35 can be equal to the second output S232 dec = 53.

[0234] In response to the last two bits of the updated word line address Add CBR being BF and the last two bits of the column hammer target word line address Add LRH being 35, according to the operation of the logic gate 233, the third output S233hex can be BF (e.g., OR). In some embodiments, the third output S233 hex = BF can be equal to the third output S233 dec = 191.

[0235] In response to updating the character line address Add CBR whose last 2 bits are BF and the column hammer target character line address Add LRH whose last 2 bits are 35, according to the operation of logic gate 234, the fourth output S234 hex can be 40 (e.g., NOR). In some embodiments, the fourth output S234 hex = 40 can be equal to the fourth output S234 dec = 64.

[0236] For the fourth update cycle CBR+3, switch 235” can select the fourth output S234 as the first number 23A. The first number 23A can be hexadecimal 40 (decimal 64), and thus does not exceed the first predetermined number (e.g., decimal 171). Without triggering the operation of the value adjuster 26, the first number 23A can be the same as the modified first number 23B for input to the counter 24. Thus, the initial countdown CDN hex (the initial value of counter 24), i.e., the modified first number 23B, can be hexadecimal 40. In some embodiments, the initial countdown value CDN hex = 40 can be equal to the initial countdown value CDN dec = 64. In this case, the counter 24 can count down from 64, and the address register 25 can be configured to obtain the character line address accessed at act_64 between update cycles CBR+3 and CBR+4 (please refer to Figure 4D ).

[0237] Figure 4D is schematic Figure 4D , illustrating in some embodiments of the present disclosure the character line addresses accessed between update cycles CBR+3 and CBR+4 along the time axis, as well as the updated character line address Add CBR in each update cycle, the column hammer target character line address Add LRH and the initial countdown value CDN.

[0238] Please refer to Figure 4D, access the word line address WL with a value of 1235 at the start of act_1. Access the word line address WL with a value of 0021 at the start of act_2. Access the word line address WL with a value of 1235 at the start of act_3. Access the word line address WL with a value of 1235 at the start of act_63. Access the word line address WL with a value of 0021 at the start of act_64. Access the word line address WL with a value of 1235 at the start of act_N-1. Access the word line address WL with a value of 0021 at the start of act_N. That is, only access the word line addresses with values of 1235 and 0021.

[0239] In the update cycle CBR+3, update the word line address Add CBR can be 1ABF, the column hammer target word line address Add LRH can be 1235. As Figure 4C shown, in response to the update word line address Add CBR having the last 2 bits as BF and the column hammer target word line address Add LRH having the last 2 bits as 35, in the update cycle CBR+3, the initial countdown value CDN hex can be hexadecimal 40. In some embodiments, the initial countdown value CDN hex = 40 can be equal to the initial countdown value CDN dec = 64. In this case, the counter 24 can start counting down from 64, and the address register 25 can be configured to obtain the word line address accessed at the start of act_64 between the update cycles CBR+3 and CBR+4, which is WL with a value of 0021. Accordingly, in the subsequent update cycle CBR+4, the column hammer target word line address Add LRH will also be 0021. That is, in the update cycle CBR+4, the adjacent word line addresses with a value of 0021 (such as the word line addresses 0020 or 0022) can be protected.

[0240] In the update cycle CBR+4, update the word line address Add CBR can be 1AC0, the column hammer target word line address Add LRH can be 0021. The word line address WL of hexadecimal 1AC0 can be equivalent to decimal 6848, and is equivalent to 0001101011000000.

[0241] In response to the update word line address Add CBR having the last 2 bits as C0 and the column hammer target word line address Add LRH having the last 2 bits as 21, according to the operation of the logic gate 231, the first output S231 hexCan be E1 (e.g., XOR). In some embodiments, the first output S231 hex = E1 can be equal to the first output S231 dec = 225.

[0242] In response to updating the character line address Add CBR The last 2 bits of which are C0 and the column hammer target character line address Add LRH The last 2 bits of which are 21, according to the operation of logic gate 232, the second output S232 hex Can be 00 (e.g., AND). In some embodiments, the second output S232 hex = 00 can be equivalent to the second output S232 dec = 0.

[0243] In response to updating the character line address Add CBR The last 2 bits of which are C0 and the column hammer target character line address Add LRH The last 2 bits of which are 21, according to the operation of logic gate 233, the third output S233 hex Can be E1 (e.g., OR). In some embodiments, the third output S233 hex = E1 can be equal to the third output S233 dec = 225.

[0244] In response to updating the character line address Add CBR The last 2 bits of which are C0 and the column hammer target character line address Add LRH The last 2 bits of which are 21, according to the operation of logic gate 234, the fourth output S234 hex Can be 1E (e.g., NOR). In some embodiments, the fourth output S234 hex = 1E can be equal to the fourth output S234 dec = 30.

[0245] For the fifth update cycle CBR + 4, switch 235” can select the first output S231 as the first number 23A. The first number 23A can be hexadecimal E1 (decimal 225), thus exceeding the first predetermined number (e.g., decimal 171). After the operation of the numerical adjuster 26, the first number 23A can be reset to zero to become the modified first number 23B input to the counter 24. Therefore, the initial countdown value CDN hex (The initial value of counter 24), i.e., the modified first number 23B, can be hexadecimal 61. In some embodiments, the initial countdown value CDN hex = 61 can be equal to the initial countdown value CDN dec= 97. In this case, the counter 24 can count down starting from 97, and the address register 25 can be configured to obtain the character line address (not shown in the figure) accessed at the start act_97 between the update cycles CBR + 4 and CBR + 5.

[0246] Please refer to Figures 4A to 4D , the address of the character line to be protected can be randomly selected from those character lines that are valid during two update cycles. The character line is selected from the character lines started between the update cycles. In this case, the selection pool includes the character lines started between the update cycles (i.e., the character line addresses of 0021 and 1235).

[0247] Figure 5 is a schematic diagram illustrating a value adjuster 26 included in a memory element in some embodiments of the present disclosure. The value adjuster 26 is Figure 2 the embodiment of the value adjuster 26 shown. The value adjuster 26 is configured to reset the most significant bit (msb) of the first number 23A when the first number 23A is greater than the first predetermined number.

[0248] Please refer to Figure 5 , the value adjuster 26 may include a judgment unit 261 and an AND gate 262. The judgment unit 261 can be configured to receive the first number 23A from the random number generator 23. In some embodiments, the judgment unit 261 can be configured to judge whether the first number 23A is greater than the first predetermined number and output a judgment result 2610.

[0249] The AND gate 262 may have one input terminal connected to the random number generator 23, another input terminal connected to the judgment unit 261, and an output terminal connected to the counter 24. In some embodiments, the AND gate 262 can be configured to receive the most significant bit Bit7 of the first number 23A and the judgment result 2610, and generate an AND output 2620 in response to the most significant bit Bit7 of the first number 23A and the judgment result 2610. In some embodiments, the AND gate 262 can be configured to transmit the AND output 2620 as the most significant bit Bit7' of the modified first number 23B to the counter 24.

[0250] In principle, the output of a two-input AND gate is true only when all input values are logical "1", and if not all inputs to the AND gate are logical "1", the output is false.

[0251] Based on this calculation of the AND gate 262, the AND output 2620 can be represented as Truth Table 1.

[0252] Bit7 2610 2620 / Bit7' 0 0 0 0 1 0 1 0 0 1 1 1

[0253] Truth Table 1

[0254] In some embodiments, a logic high of the determination result 2610 indicates that the first number 23A is less than a predetermined number. Conversely, a logic low of the determination result 2610 indicates that the first number 23A is greater than the predetermined number. Thus, when the determination result 2610 is logic low (logic "0") and Bit7 of the first number 23A is logic high (logic "1"), the AND output 2620 will be logic low to reduce the first number 23A to the modified first number 23B. That is, the most significant bit (msb) of the first number 23A can be reset to logic "0". In some embodiments, when the first number 23A is greater than a first predetermined number, the numerical adjuster 26 can be configured to subtract 128 (i.e., 2 7 ) from the first number 23A to obtain the modified first number 23B. For example, when the first number 23A is 171 and greater than the first predetermined number 170, the numerical adjuster 26 can subtract 128 from the first number 23A to produce the modified first number 23B as 42.

[0255] The determination unit 261 can be a circuit including one or more logic gates. In some embodiments, the determination unit 261 can include a first part 2611, a second part 2612, and a logic gate L8.

[0256] In some embodiments, the first part 2611 can include two AND gates L6 and L7. Two input terminals of the AND gate L6 are connected to the random number generator 23 and are configured to receive Bit5 and Bit7 of the first number 23A respectively. The AND gate L6 is configured to generate an output L60 at the output terminal in response to Bit5 and Bit7 of the first number 23A. The AND gate L7 can have three input terminals connected to the random number generator 23 and is configured to receive Bit4, Bit5, and Bit7 of the first number 23A respectively. The AND gate L7 is configured to generate an output L70 at the output terminal in response to Bit4, Bit5, and Bit7 of the first number 23A.

[0257] The first part 2611 can be configured to determine whether a first part of the binary sequence of the first number 23A is greater than a first critical value. In some embodiments, when the first number 23A is represented by an 8-bit binary sequence, the first part of the binary sequence of the first number 23A can be 4 bits (e.g., the first four digits). In some embodiments, the first critical value can be represented by a 4-bit binary sequence (e.g., the first four digits of the first predetermined number). For example, if the first predetermined number is 170, which can be represented in binary as 10101010, then the first critical value can be represented in binary as 1010.

[0258] In some embodiments, the second part 2612 includes AND gates L1, L2, L4, and L5 and an OR gate L3. AND gate L1 may have three input terminals connected to the random number generator 23 and is configured to receive Bit0, Bit1, and Bit3 of the first number 23A respectively. AND gate L1 is configured to generate an output L10 at the output terminal in response to Bit0, Bit1, and Bit3 of the first number 23A. AND gate L2 may have two input terminals connected to the random number generator 23 and is configured to receive Bit2 and Bit3 of the first number 23A respectively. AND gate L2 is configured to generate an output L20 at the output terminal in response to Bit2 and Bit3 of the first number 23A. The output terminals of AND gates L1 and L2 are connected to OR gate L3 as inputs. OR gate L3 is configured to generate an output L30 at the output terminal in response to outputs L10 and L20.

[0259] Two input terminals of AND gate L4 are connected to the random number generator 23 and are configured to receive Bit5 and Bit7 of the first number 23A respectively. AND gate L4 is configured to generate an output L40 at the output terminal in response to Bit5 and Bit7 of the first number 23A. AND gate L5 may have two input terminals connected to OR gate L3 and AND gate L4 respectively and is configured to receive outputs L30 and L40 respectively. AND gate L5 is configured to generate an output L50 at the output terminal in response to outputs L30 and L40.

[0260] The second part 2612 may be configured to determine whether a second part of the binary sequence of the first number 23A is greater than a second critical value when the first part of the binary sequence of the first number 23A is greater than or equal to the first critical value. In some embodiments, when the binary sequence of the first number 23A is 8 bits, the second part of the binary sequence of the first number 23A may be 4 bits (e.g., the last four digits). In some embodiments, the second critical value may be represented by a 4-bit binary sequence (e.g., the last four digits of the first predetermined number). For example, if the first predetermined number is 170, which can be represented in binary as 10101010, then the second critical value can be represented in binary as 1010. In some embodiments, AND gate L4 is configured to determine whether the first part of the binary sequence of the first number 23A is greater than or equal to the first critical value.

[0261] In some embodiments, each of the first part 2611 and the second part 2612 may compare a part of the first number 23A with the corresponding part of the first predetermined number. Then, the logic gate L8 may combine the results of the first part 2611 and the second part 2612 and output a final judgment result (i.e., the judgment result 2610).

[0262] In some embodiments, the logic gate L8 can be a NOR gate. The NOR gate L8 can be connected to the first part 2611 and the second part 2612. In some embodiments, the NOR gate L8 can have three input terminals respectively connected to the AND gates L5, L6, and L7, and is configured to receive the outputs L50, L60, and L70 respectively. In some embodiments, the NOR gate L8 is configured to generate a judgment result 2610 at the output terminal in response to the outputs L50, L60, and L70. Based on such a calculation of the NOR gate L8, the judgment result 2610 can be represented as truth table 2.

[0263] L50 L60 L70 2610 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 1 1 0 1 0 1 0 1 1 0 0 1 1 1 0

[0264] Truth table 2

[0265] Only when the outputs L50, L60, and L70 are all logic "0", the NOR gate L8 outputs logic "1". In some embodiments, a logic high of the judgment result 2610 indicates that the first number 23A is less than a predetermined number. Conversely, a logic low of the judgment result 2610 indicates that the first number 23A is greater than the predetermined number. In this case, when the judgment result 2610 is logic low and Bit7 of the first number 23A is logic high, the most significant bit (msb) of the first number 23A can be reset to logic "0".

[0266] Taking the first predetermined number as 170 as an example, when the first number 23A is 127, 128, 170, 171, and 187, the outputs of the logic gates of the numerical adjuster 26 can be represented as Tables 1 to 5 respectively.

[0267] 23A Bit7 Bit6 Bit5 Bit4 Bit3 Bit2 Bit1 Bit0 127 0 1 1 1 1 1 1 1 L10 L20 L30 L40 L50 L60 L70 2610 2620 1 1 1 0 0 0 0 1 0

[0268] Table 1

[0269] 23A Bit7 Bit6 Bit5 Bit4 Bit3 Bit2 Bit1 Bit0 128 1 0 0 0 0 0 0 0 L10 L20 L30 L40 L50 L60 L70 2610 2620 0 0 0 0 0 0 0 1 1

[0270] Table 2

[0271] 23A Bit7 Bit6 Bit5 Bit4 Bit3 Bit2 Bit1 Bit0 170 1 0 1 0 1 0 1 0 L10 L20 L30 L40 L50 L60 L70 2610 2620 0 0 0 1 0 0 0 1 1

[0272] Table 3

[0273] 23A Bit7 Bit6 Bit5 Bit4 Bit3 Bit2 Bit1 Bit0 171 1 0 1 0 1 0 1 1 L10 L20 L30 L40 L50 L60 L70 2610 2620 1 0 1 1 1 0 0 0 0

[0274] Table 4

[0275] 23A Bit7 Bit6 Bit5 Bit4 Bit3 Bit2 Bit1 Bit0 187 1 0 1 1 1 0 1 1 L10 L20 L30 L40 L50 L60 L70 2610 2620 1 0 1 1 1 0 1 0 0

[0276] Table 5

[0277] Figure 5The illustrated determination unit 261 is an example circuit that determines whether the first number 23A is greater than a first preset number. In some embodiments, the determination unit 261 can also be implemented by other configurations for determining whether the first number 23A is greater than the same first predetermined number. In other embodiments, in order to compare the first number with different first predetermined numbers, the determination unit 261 can be implemented by different configurations as needed.

[0278] The value adjuster 26 is used to determine whether a random number (i.e., the first number 23A) exceeds a first predetermined number (i.e., the maximum number of start-ups between two update cycles), and then modifies the random number to a range from 0 to a first determination number. The value adjuster 26 modifies the most significant bit of the first number 23A so that the first number 23A can be slightly modified to maintain randomness. The operation of the value adjuster 26 is independent of the processing of the random number generator 23, so it does not affect the randomness of the first number 23A.

[0279] Figure 6 is a flowchart illustrating a protection method 6 for a memory element according to some embodiments of the present disclosure. In some embodiments, the protection method 6 is used to protect a word line included in a memory element. In some embodiments, the memory element may include multiple word lines.

[0280] In step 61, a first output can be generated through a first logic gate according to an address of a first word line and an address of a first accessed word line, where the adjacent word lines of the first word line and the first accessed word line are updated during a first update cycle. In some embodiments, the first logic gate (e.g., Figure 2B the logic gate 231 in CBR can be configured to generate a first output S231 according to the address of the word line Add LRH and the address of the accessed word line Add

[0281] In some embodiments, a controller of the memory element (e.g., Figure 2 the controller 22 in Figure 4B can update one or more word lines in each update cycle in response to an update signal. In some embodiments, in the first update cycle (e.g., LRH the update cycle CBR + 1 in

[0282] the controller can be configured to update a normal word line (e.g., the word line address of 1ABD) and a high-risk bit line (e.g., the word line addresses of 0020 or 0022, adjacent to Add CBRThe last two bits are BD and the column hammer target character line address is Add LRH The last two bits are 21, and the first output S231 can be 9C in hexadecimal (156 in decimal) according to the operation (e.g., XOR) of logic gate 231.

[0283] In step 62, a second output can be generated by a second logic gate according to the address of the first character line and the address of the first accessed character line. In some embodiments, the second logic gate (e.g., Figure 2B the logic gate 232 in CBR can be configured to generate a second output S232 according to the address of character line Add LRH and the address of the accessed character line Add Figure 4B For example, in response to updating the character line address Add CBR whose last two bits are BD and the column hammer target character line address Add LRH whose last two bits are 21, the second output S232 can be 21 in hexadecimal (33 in decimal) according to the operation (e.g., AND) of logic gate 232.

[0284] In step 63, one of the first output and the second output can be selected as a first number by a multiplexer in response to a selection signal. In some embodiments, the multiplexer (e.g., Figure 2 the multiplexer 235 in

[0285] can be configured to select one of the first output S231 and the second output S232 as the first number 23A in response to the selection signal S0. In some embodiments, once the first number 23A exceeds a first predetermined number (e.g., 171), the first number 23A can be processed by the numerical adjuster 26 as a modified first number 23B. Figure 2 In step 64, a counter can count down from the first number. In some embodiments, the counter (e.g., Figure 2 the counter 24 in

[0286] counts down from the first number 23A in response to the update signal RS. In some embodiments, each countdown is triggered by an access signal indicating the access to a character line. In some embodiments, step 64 can be performed by Figure 4B the counter 24 shown in Figure 2in the address register 25 shown. The controller (e.g., Figure 2 the controller 22 in) can be configured to access the address register 25 and obtain the address of the second access character line. In some embodiments, step 65 can be performed by the controller 22 with / without Figure 2 the address register 25 shown.

[0287] In step 66, a second protected character line can be updated during a second update period, where the second protected character line is adjacent to the second accessed character line. In some embodiments, the second protected character line can be updated during the second update period (e.g., the character line addresses of 1234 or 1236 can be updated during the update period CBR+2, as Figure 4B shown). In some embodiments, step 66 can be performed by Figure 2 the controller 22 in.

[0288] To implement a column hammer, a malicious operator often accesses one or more target character lines at a high frequency. A large number of accesses to the target character lines can cause a column hammer effect on the character lines adjacent to the target character lines. That is, under the column hammer effect, even if the nearby character lines are not accessed, the content of the nearby character lines may change due to the leaked charge.

[0289] The present disclosure provides a memory element that can determine a target character line that may be attacked and protect the character lines adjacent to the possible target character lines. A random number generator can generate a random number as the initial value of a counter, and the accessed target character line address can be obtained when the counter is decremented to zero. Specifically, the random number generator includes one or more logic gates that can generate a random number according to the updated character line address and the target character line address in the previous update period. The random number generator can also include a switch for selecting, from the outputs of the logic gates, the random number to be output to the counter. Therefore, the value generated by the random number generator may be difficult to predict. In addition, in order to prevent the random number from exceeding the maximum number of starts between update periods, a value adjuster modifies the random number to a range from zero to a predetermined number (i.e., the maximum number of starts between update periods). Therefore, the character lines adjacent to the frequently accessed target character lines can be updated to maintain the content.

[0290] One embodiment of the present disclosure provides a memory element. The memory element includes a plurality of word lines, a random number generator, a counter, and a controller. The random number generator is configured to receive an address of a first word line and an address of a first accessed word line, wherein adjacent word lines of the first word line and the first accessed word line are updated during a first update period. The random number generator includes a first logic gate, a second logic gate, and a switch. The first logic gate is configured to generate a first output according to the address of the first word line and the address of the first accessed word line. The second logic gate is configured to generate a second output according to the address of the first word line and the address of the first accessed word line. The switch is electrically coupled to the first logic gate and the second logic gate to select one of the first output and the second output as a first number. The counter is electrically coupled to the random number generator, and the counter is configured to receive the first number and count down from the first number. The controller is configured to obtain an address of a second accessed word line being accessed when the counter counts down to zero, and update adjacent word lines of the second accessed word line during a second update period.

[0291] Another embodiment of the present disclosure provides a memory element. The memory element includes a plurality of word lines, a random number generator, a counter, an address register, and a controller. The random number generator is configured to receive an address of a first word line and an address of a first accessed word line, wherein adjacent word lines of the first word line and the first accessed word line are updated during a first update period. The random number generator includes a first logic gate, a second logic gate, and a switch. The first logic gate is configured to generate a first output according to the address of the first word line and the address of the first accessed word line. The second logic gate is configured to generate a second output according to the address of the first word line and the address of the first accessed word line. The switch is electrically coupled to the first logic gate and the second logic gate to select one of the first output and the second output as a first number. The counter is electrically coupled to the random number generator and is configured to receive the first number and count down from the first number. The address register is electrically coupled to the counter and is configured to store an address of a second accessed word line that is valid when the counter counts down to zero. The controller is configured to access the address register to obtain the address of the second accessed word line, and protect adjacent word lines of the second accessed word line during a second update period.

[0292] Another embodiment of the present disclosure provides a method for protecting a memory element, where the memory element includes a plurality of word lines. The protection method includes generating a first output by a first logic gate according to an address of a first word line and an address of a first accessed word line, where adjacent word lines of the first word line and the first accessed word line are updated during a first update period; generating a second output by a second logic gate according to the address of the first word line and the address of the first accessed word line; selecting, by a multiplexer in response to a selection signal, one of the first output and the second output as a first number; counting down from the first number by a counter; when the counter counts to zero, obtaining, by a controller, an address of a second accessed word line being accessed; and updating a second protected word line during the second update period, where the second protected word line is adjacent to the second accessed word line.

[0293] Embodiments of the present disclosure provide a memory element having a protection circuit for selecting and protecting vulnerable word lines. Specifically, the protection circuit of the memory element can protect the word lines (memory cells) from column hammering. To trigger column hammering, a malicious operator would quickly activate the same memory column, causing charge leakage on adjacent unactivated memory columns. This protection circuit provides a random number generator and a counter to randomly select and protect a potentially attacked memory column. The counter can be configured to count down from a random number generated by the random number generator. When the counter reaches zero, the address of the activated memory column can be obtained. In other words, the memory column is selected from the memory columns activated between update periods. In this case, the selection pool includes the memory columns activated between update periods. The random number generator can generate a random number according to the address of the last updated word line and the address of the last accessed word line (the selected potentially attacked word line) to increase the unpredictability of the random number. Specifically, the random number generator can include one or more logic gates that generate a random number according to the updated word line address and the target word line address in the previous update period. The random number generator can also include a switch for selecting, among the outputs of the logic gates, the random number to be output to the counter, making the number generated by the random number generator more difficult to predict.

[0294] In addition, to prevent the random number generated by the random number generator from exceeding the maximum number of activations between update periods, the value adjuster modifies the random number to a range from zero to a predetermined number (i.e., the maximum number of activations between update periods). Since the memory columns adjacent to the activated memory column are more vulnerable to the column hammer effect, they will be protected in subsequent update periods.

[0295] Under normal circumstances, the activation amount of the trigger column hammer cannot be completed within two update cycles. For example, a memory element with 8192 columns can have approximately 170 activations between update cycles, and the activation amount of the trigger column hammer in the same column can be 10,000 or more. Therefore, protecting additional vulnerable memory columns in each update cycle can eliminate the column hammer problem. In addition, the memory element can include a value adjuster circuit to determine whether the random number used to select one of the memory columns exceeds the maximum activation amount between update cycles (i.e., 170 in this case), and then reduce the random number to the range of 0 to 170, improving the security and performance of the memory element.

[0296] Although the present disclosure and its advantages have been described in detail, it should be understood that various changes, substitutions, and alternatives can be made without departing from the spirit and scope of the present disclosure as defined by the claims. For example, many of the above processes can be implemented in different ways, and many of the above processes can be replaced by other processes or combinations thereof.

[0297] Furthermore, the scope of the present application is not limited to the specific embodiments of the processes, machines, manufactures, compositions of matter, means, methods, and steps described in the specification. Those skilled in the art can understand from the disclosure of the present disclosure that existing or future-developed processes, machines, manufactures, compositions of matter, means, methods, or steps that have the same function or achieve substantially the same result as the corresponding embodiments described herein can be used according to the present disclosure. Accordingly, these processes, machines, manufactures, compositions of matter, means, methods, or steps are included in the claims of the present application.

Claims

1. A memory element, comprising: Multiple word lines; A random number generator configured to receive an address of a first word line and an address of a first accessed word line, wherein adjacent word lines of the first word line and the first accessed word line are updated during a first update period, and wherein the random number generator includes: A first logic gate configured to generate a first output based on the address of the first word line and the address of the first accessed word line; A second logic gate configured to generate a second output based on the address of the first word line and the address of the first accessed word line; and A switch electrically coupled to the first logic gate and the second logic gate for selecting one of the first output and the second output as a first number; and A counter electrically coupled to the random number generator, wherein the counter is configured to receive the first number and count down from the first number; and A controller configured to obtain an address of a second accessed word line being accessed when the counter counts down from the first number to zero, and update adjacent word lines of the second accessed word line during a second update period.

2. The memory element according to claim 1, wherein the random number generator further includes a third logic gate configured to generate a third output based on the address of the first word line and the address of the first accessed word line.

3. The memory element according to claim 2, wherein the switch is configured to sequentially select the first output, the second output, and the third output as the first number in response to a selection signal in each update period.

4. The memory element according to claim 2, wherein the switch is configured to randomly select the first output, the second output, and the third output as the first number in response to a selection signal in each update period.

5. The memory element according to claim 1, wherein the first logic gate and the second logic gate include different types of logic gates.

6. The memory element according to claim 1, wherein the first logic gate includes one of an OR gate, an AND gate, a NOR gate, a NAND gate, an XOR gate, or an XNOR gate.

7. The memory element according to claim 1, wherein the switch includes a multiplexer.

8. The memory element according to claim 1, wherein both the address of the first word line and the address of the first accessed word line are represented by a 4-bit hexadecimal sequence.

9. The memory element according to claim 8, wherein the random number generator is configured to generate the first number based on a first portion of the address of the first word line and a first portion of the address of the first accessed word line.

10. The memory element according to claim 1, wherein the controller is further configured to update a second word line during the second update period.

11. A memory element, comprising: Multiple word lines; A random number generator configured to receive an address of a first character line and an address of a first accessed character line, wherein adjacent character lines of the first character line and the first accessed character line are updated during a first update period, and the random number generator includes: A first logic gate configured to generate a first output based on the address of the first character line and the address of the first accessed character line; A second logic gate configured to generate a second output based on the address of the first character line and the address of the first accessed character line; and A switch electrically coupled to the first logic gate and the second logic gate for selecting one of the first output and the second output as a first number; and A counter electrically coupled to the random number generator, wherein the counter is configured to receive the first number and count down from the first number; An address register electrically coupled to the counter and configured to store an address of a second accessed character line that is valid when the counter counts down to zero; and A controller configured to access the address register to obtain the address of the second accessed character line and protect adjacent character lines of the second accessed character line during a second update period.

12. The memory element according to claim 11, wherein the random number generator further includes a third logic gate configured to generate a third output based on the address of the first character line and the address of the first accessed character line.

13. The memory element according to claim 12, wherein the switch is configured to sequentially select the first output, the second output, and the third output as the first number in response to a selection signal in each update period.

14. The memory element according to claim 12, wherein the switch is configured to randomly select the first output, the second output, and the third output as the first number in response to a selection signal in each update period.

15. The memory element according to claim 11, wherein the first logic gate and the second logic gate include different types of logic gates.

16. The memory element according to claim 11, wherein the first logic gate includes one of an OR gate, an AND gate, a NOR gate, a NAND gate, an XOR gate, or an XNOR gate.

17. The memory element according to claim 11, wherein the switch includes a multiplexer.

18. The memory element according to claim 11, wherein both the address of the first character line and the address of the first accessed character line are represented by a hexadecimal sequence having 4 bits.

19. The memory element according to claim 18, wherein the random number generator is configured to generate the first number based on a first portion of the address of the first character line and a first portion of the address of the first accessed character line.

20. The memory element according to claim 11, further including a value adjuster configured to reset a most significant bit of the first number when the first number is greater than a first predetermined number.

Citation Information

Patent Citations

  • Physically unclonable function with precharge through bit lines

    CN113535123A

  • Semiconductor memory device and memory system having same

    CN114678050A

  • Apparatus and method for counteracting memory attacks

    CN115705892A

  • Memory device capable of determining candidate wordline for refresh

    TW201837910A

  • Immunity Against Temporary and Short Power Drops in Non-Volatile Memory: Pausing Techninques

    US20130265838A1