Flash memory physical destruction method and system based on negative voltage injection
Patent Information
- Application Number
- CN202611239696.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-17
- Publication Date
- 2026-09-22
AI Technical Summary
若销毁前缺少可靠的正常供电隔离和残余电荷处理,高压或大电流冲击可能通过供电网络、保护器件或板级寄生路径耦合至非目标电路,不仅影响目标闪存芯片的实际受力,还可能造成主控及外围电路异常损坏
[0012] (1) By shutting down the normal power supply path of each NAND after the destruction enable signal is effective and latching the normal power supply prohibition state, and at the same time providing input power to the negative pressure generation module from the SSD onboard low voltage power supply, the problem that electrical stress is easily coupled to non-target circuits through the normal power supply network, main control interface, read and write channel or board-level parasitic path during the existing high voltage or high current destruction process is solved, and the safety control of power supply path isolation before destruction and independent power supply during destruction process is realized.
Smart Images

Figure CN122796933A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of integrated circuit technology, and in particular to a method and system for physical destruction of flash memory based on negative voltage injection. Background Technology
[0002] With the development of applications such as cloud computing, edge computing, industrial control, automotive electronics, security monitoring, and mobile terminals, solid-state drives (SSDs) are widely used as data storage media in various electronic devices. SSDs typically use multiple NAND flash memory chips as core storage units, with data writing, reading, erasing, and management handled by a controller, power supply circuitry, read / write channels, and board-level peripheral circuitry. Because NAND flash memory is non-volatile, the data stored within it can be preserved for a long time even when the device is powered off. Therefore, in devices involving sensitive data, classified data, authentication data, log data, or business-critical data, how to achieve reliable data destruction under specific conditions is a crucial aspect of the security design of SSD devices. In scenarios such as device scrapping, device loss of control, emergency response, data security protection, and anti-tampering / reading, simply erasing data through file deletion, formatting, logical erasure, or controller commands usually still relies on the normal execution of the storage controller and firmware processes. When a solid-state drive (SSD) controller fails, access permissions are lost, the device is disassembled, or the NAND Flash chip is removed for offline analysis, there is still a risk of data being retrieved through chip-level reading, residual information analysis, or recovery from the underlying storage unit. Therefore, for high-security SSDs, in addition to logical destruction, physical destruction methods that can directly affect the NAND Flash chip itself are necessary to prevent the chip from retaining or outputting valid data.
[0003] In solid-state drives (SSDs), multiple NAND flash chips typically reside within the same board-level circuitry, with complex interconnections between their power supply terminals, ground terminals, chip select lines, read / write channels, protection structures, and external power supply networks. During physical destruction, the destruction energy must not only act on the target memory chip but also consider the impact of the board-level power supply network, residual charge, common connection nodes, and external low-voltage circuits. Without a destruction control method adapted to the SSD board-level structure, the physical destruction process is difficult to coordinate with the arrangement, power supply paths, and detection paths of the multiple NAND flash chips. Therefore, in the field of secure SSD storage, a physical destruction technology adapted to the board-level structure of multiple NAND flash chips is needed. This technology should enable orderly control and confirmation of the power supply status, residual voltage status, destruction energy access status, and post-destruction electrical parameter status of each memory chip after destruction is triggered. This type of technology is crucial for improving the data unrecoverability, emergency response capabilities, and board-level destruction controllability of SSDs in high-security scenarios.
[0004] Existing chip physical destruction devices based on electrical energy storage typically use a charge pump to increase the operating voltage to above the chip destruction voltage and store the boosted electrical energy in a storage capacitor. When destruction is required, a disconnecting switch connects the storage capacitor to the chip to be destroyed, allowing the storage capacitor to release high-voltage electrical energy to the chip, thus achieving physical chip destruction. This type of solution mainly relies on a charge pump to boost voltage, a storage capacitor to store energy, and a disconnecting switch to release energy to complete the destruction process.
[0005] Current physical destruction methods for NAND Flash typically involve applying an external positive high voltage, energy storage high voltage, or instantaneous high current to the power supply terminals of the flash chip, causing breakdown or ablation of the internal structure. However, when multiple flash chips are arranged in the same solid-state drive board circuit, the power traces, parasitic impedance, packaging structure, protection structure conduction characteristics, and low-resistance paths on the board are not entirely consistent. The surge current tends to be released preferentially along local low-resistance paths, resulting in some chips experiencing insufficient actual electrical stress, while others may suffer excessive impact. This leads to inconsistent damage levels among different flash chips, resulting in uncontrollable destruction outcomes.
[0006] Current physical destruction processes often follow fixed high-voltage amplitudes, fixed conduction times, or uniform triggering strategies. They typically only focus on whether the destruction voltage has been output or whether a preset time has elapsed, lacking the identification of current surges, impedance changes, and actual failure states of individual flash memory chips during the destruction process. Due to differences in the internal protection structures, parasitic conduction paths, and power rail structures of different flash memory chips, even when the same voltage and duration are applied, some chips may have already suffered irreversible damage, while others may only experience transient conduction or localized damage. It is difficult to determine whether further impact is necessary or whether a stable failure state has been reached.
[0007] Furthermore, in the solid-state drive (SSD) board-level environment, the normal operating power supply, controller, read / write channels, and other peripheral low-voltage circuits of flash memory chips are typically connected to the flash memory power network. If reliable normal power supply isolation and residual charge handling are lacking before destruction, high-voltage or high-current surges may couple to non-target circuits through the power network, protection devices, or board-level parasitic paths. This not only affects the actual stress on the target flash memory chip but may also cause abnormal damage to the controller and peripheral circuits. Existing methods struggle to simultaneously ensure chip-by-chip destruction consistency, board-level circuit isolation security, and confirmable destruction status. Summary of the Invention
[0008] Based on this, the present invention provides a flash memory physical destruction method and system based on negative voltage injection, which can realize the one-by-one, controllable and verifiable physical destruction of multiple flash memory chips in a solid-state drive board-level environment, improving destruction consistency, power supply isolation security and negative voltage release reliability under abnormal conditions.
[0009] Firstly, a method for physical destruction of flash memory based on negative voltage injection is provided, applicable to solid-state drives including multiple flash memory chips. This method includes: receiving and confirming the validity of a destruction enable signal; shutting off or isolating the normal operating power supply path of each flash memory chip; outputting a power enable signal to generate a negative voltage output with a negative value relative to the ground terminal from the onboard low-voltage power supply of the negative voltage generation module; outputting multiple control enable signals in a preset sequence, with the multi-channel MOS control circuit turning on the corresponding destruction MOS branch of the current flash memory chip, so that the negative voltage output is connected to the power supply terminal of the current flash memory chip, forming a negative injection voltage between its power supply terminal and ground terminal; keeping the current destruction MOS branch on for a preset single injection duration, causing the current flash memory chip to physically fail; shutting off the current destruction MOS branch and switching to the next flash memory chip, until all target flash memory chips have been processed and the negative voltage generation module is shut down.
[0010] Secondly, a flash memory physical destruction system based on negative voltage injection is provided for solid-state drives (SSDs) containing multiple flash memory chips. The system includes: a controller, a destruction enable interface, an onboard low-voltage power supply input, a normal operating power supply, a normal operating power supply isolation unit, a negative voltage generation module, a multi-channel MOS control circuit, a current sampling unit, a VCC-GND impedance detection unit, a residual voltage detection unit, a residual release branch, a common negative voltage output node release unit, and a parameter storage unit. The destruction enable interface is connected to the controller and outputs a destruction enable signal. The normal operating power supply isolation unit is connected between the normal operating power supply and the power supply terminals of each flash memory chip, used to shut down or isolate the normal operating power supply path of each flash memory chip under the control of the controller. The negative voltage generation module is connected to the onboard low-voltage power supply input and generates a negative voltage output with a negative value relative to the ground terminal under the action of the power enable signal output by the controller. The output terminal of the negative voltage generation module forms a common negative voltage output node. The multi-channel MOS control circuit includes multiple... Each flash memory chip has a corresponding multiple destruction MOS branch. Each destruction MOS branch is connected between the common negative voltage output node and the power supply terminal of the corresponding flash memory chip. It is used to turn on the destruction MOS branch corresponding to the current flash memory chip under the action of the multi-channel control enable signal output by the controller, and keep the other destruction MOS branches off. The current sampling unit is used to collect the injection current of the destruction MOS branch corresponding to the current flash memory chip. The VCC-GND impedance detection unit is used to detect the equivalent impedance before and after injection between the power supply terminal and the ground terminal of the current flash memory chip. The residual voltage detection unit is used to detect the residual voltage of the power supply terminal of each flash memory chip relative to the ground terminal. The residual release branch is used to release the residual charge of the power supply terminal of the corresponding flash memory chip. The common negative voltage output node release unit is used to release the charge of the common negative voltage output node when all target flash memory chips have been processed or a global anomaly is triggered. The parameter storage unit is used to store threshold parameters, duration parameters, current parameters, impedance parameters and corresponding preset emergency values.
[0011] The beneficial effects achieved by the provided technical solution include at least the following:
[0012] (1) By shutting down the normal power supply path of each NAND after the destruction enable signal is effective and latching the normal power supply prohibition state, and at the same time providing input power to the negative pressure generation module from the SSD onboard low voltage power supply, the problem that electrical stress is easily coupled to non-target circuits through the normal power supply network, main control interface, read and write channel or board-level parasitic path during the existing high voltage or high current destruction process is solved, and the safety control of power supply path isolation before destruction and independent power supply during destruction process is realized.
[0013] (2) By detecting the residual voltage of VCC_i of each NAND to GND before negative pressure injection, and releasing the residual charge through the corresponding residual release branch when the residual voltage does not meet the standard, the problem of inconsistent initial voltage state of each chip power supply terminal before destruction and the residual charge affecting the negative pressure injection start condition is solved. This achieves that multiple NAND chips have a relatively consistent and verifiable electrical initial state before entering negative pressure injection.
[0014] (3) The negative voltage output with a negative value relative to the ground terminal is generated by the low voltage power supply on the SSD board, and the controller outputs multiple control enable signals in a preset order, so that the multi-channel MOS control circuit turns on the destruction MOS branch corresponding to the current NAND chip one by one, thereby connecting the negative voltage output to the VCC_i of the current NAND chip one by one. This solves the problems of voltage drop, energy diversion, priority discharge of local low resistance path and non-target chip stress when multiple NAND chips are connected to destruction energy at the same time. It realizes that the negative electrical stress is injected one by one along the VCC-GND path of the currently selected NAND chip.
[0015] (4) By obtaining the VCC-GND equivalent impedance reference before each NAND injection, collecting the injection current during the injection process, and detecting the VCC-GND equivalent impedance after injection, the electrical parameter failure criterion is determined based on the sudden change in injection current and the sudden change in impedance before and after injection. This solves the problem that existing methods rely solely on fixed conduction time, fixed impulse voltage, or whether high voltage is output to determine the destruction status, making it difficult to identify the actual degree of failure of a single NAND. This achieves destruction status confirmation and supplementary injection control based on changes in single-chip electrical parameters.
[0016] (5) By setting abnormal branches such as residual voltage failure, negative voltage establishment failure, impedance reference abnormality, initial short circuit abnormality, negative voltage recovery abnormality, sampling saturation and overcurrent, and through the normal power supply isolation unit, the destruction MOS branch, the negative voltage feedback sampling channel, the VCC-GND impedance detection unit, the VCC_i residual detection and release branch, the current sampling unit and the common negative voltage output node release unit work together to solve the problems of unclear abnormal boundaries in the existing destruction process, the possibility of continuing to apply electrical stress under abnormal conditions and the difficulty of integrating and verifying the board-level structure. It realizes the differentiation and processing of single-chip abnormalities and global abnormalities, abnormal shutdown and safe release of the common negative voltage output node. Attached Figure Description
[0017] Figure 1 This is a schematic diagram of the core control link for physical destruction of flash memory based on negative voltage injection according to Embodiment 1 of the present invention;
[0018] Figure 2 This is a flowchart of a flash memory physical destruction method based on negative voltage injection according to Embodiment 1 of the present invention;
[0019] Figure 3 This is an overall hardware structure diagram provided according to Embodiment 3 of the present invention;
[0020] Figure 4 This is a hardware branch diagram corresponding to a single NAND chip provided in Embodiment 3 of the present invention. Detailed Implementation
[0021] To further illustrate the technical means and effects of the present invention in achieving its intended purpose, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention, in conjunction with the accompanying drawings and preferred embodiments, is provided below.
[0022] This invention provides a method and system for physical destruction of flash memory based on negative voltage injection, which can realize the one-by-one, controllable and verifiable physical destruction of multiple flash memory chips in a solid-state drive board-level environment, improving destruction consistency, power supply isolation security and negative voltage release reliability under abnormal conditions.
[0023] Example 1: This example provides a circuit and control method for the negative voltage injection and destruction of NAND Flash memory chips based on the low-voltage power supply on the SSD (Solid State Drive) board. For example... Figure 1 The diagram shows the core control link for the physical destruction of flash memory based on negative voltage injection. This circuit is located in the SSD board-level circuitry and is used to sequentially inject negative electrical stress (VCC-GND, between the power supply and ground terminals) into multiple NAND flash chips within the SSD after receiving a destruction enable signal. The circuit includes a controller, a destruction enable interface, an onboard low-voltage power supply input, a NAND normal operation power supply, a normal power supply isolation unit, a negative voltage generation module, a multi-channel MOS control circuit, a current sampling unit, a VCC-GND impedance detection unit, a VCC_i residual voltage detection unit, a VCC_i residual release branch, a common negative voltage output node release unit, and multiple NAND chips. The NAND normal operation power supply provides the normal operation voltage to the VCC_i of each NAND chip during normal SSD read / write operations; the onboard low-voltage power supply input provides low-voltage input power to the controller and the negative voltage generation module. After the destruction process is initiated, the controller shuts off the normal power supply isolation switch between the normal power supply of the NAND and the VCC_i of each NAND, so that the normal power supply of the NAND is no longer connected to the VCC_i of each NAND; the negative pressure generation module is still powered by the onboard low-voltage power supply input terminal and generates a negative pressure output for negative pressure injection. Figure 1 The main illustration shows the destruction of the enable signal, controller, negative voltage generation module, multi-channel MOS control circuit and main negative voltage injection link between NAND; the residual voltage detection, impedance detection, current sampling and common negative voltage output node release related units can be set in the SSD board level circuit and connected to the controller.
[0024] The multi-channel MOS control circuit includes multiple destroyable MOS branches corresponding one-to-one with multiple NAND chips. The multiplexing control enable signal is a multi-branch enable signal output from the controller to the multi-channel MOS control circuit. The multi-channel MOS control circuit is used to turn on the destroyable MOS branch corresponding to the current NAND chip according to the multiplexing control enable signal, while keeping the destroyable MOS branches corresponding to other NAND chips off, so that the negative voltage output from the negative voltage generation module is connected to the power supply terminal of the current NAND chip. In one specific implementation, the onboard low-voltage power supply is 5V, and the target negative voltage output by the negative voltage generation module is -12V.
[0025] Multiple NAND chips are designated as chip 1 to chip N. The power supply terminal of the i-th NAND chip is denoted as VCC_i, and its ground terminal is connected to the system GND (ground terminal). The normal power supply isolation unit includes a normal power supply isolation switch corresponding to each NAND chip. The VCC_i of each NAND chip is connected to the normal operating power supply of the NAND chip through the corresponding normal power supply isolation switch, and is connected to the common negative voltage output node through the corresponding destroyed MOS (Metal-Oxide-Semiconductor) branch. In normal operating condition, the normal power supply isolation switch is turned on, and the destroyed MOS branch is turned off; in destroyed condition, the normal power supply isolation switch is turned off, and the controller outputs an enable signal to the destroyed MOS branch corresponding to the current NAND chip in a preset sequence, causing the VCC_i of the selected i-th NAND chip to be pulled to a negative voltage state below GND. After the current NAND completes injection, detection, and result recording, the controller shuts down the destruction MOS branch corresponding to the current NAND and determines whether there is still an unprocessed next NAND. If there is an unprocessed next NAND, the controller sets the next NAND as the current processing target and outputs a conduction enable signal to the destruction MOS branch corresponding to that NAND. If there is no unprocessed next NAND, the controller shuts down the negative voltage generation module and controls the common negative voltage output node to release to a safe potential.
[0026] like Figure 2 The flowchart shown illustrates a flash memory physical destruction method based on negative voltage injection. The destruction enable signal is a binary destruction enable signal, including a triggered state and a non-triggered state. The controller detects the destruction enable signal output from the destruction enable interface. When the destruction enable signal remains in the triggered state for a duration that reaches a preset trigger confirmation time, the controller determines that the destruction enable signal is valid. When the destruction enable signal returns to the non-triggered state within the preset trigger confirmation time, the controller does not initiate the destruction process and maintains the NAND flash memory's normal power supply. The preset trigger confirmation time is read from the trigger confirmation parameter table, which is configured according to the destruction enable interface type, the destruction enable signal sampling period Ta, and the number of trigger debouncing samples N. deb Write the corresponding trigger confirmation time Tb, and Tb=Ndeb ×Ta.
[0027] After the destruction enable signal is valid, the controller shuts off the normal power supply isolation switch between the NAND normal operating power supply and the VCC_i of each NAND, and latches the normal power supply disabled state. Before this normal power supply disabled state is released, the SSD host interface, NAND read / write channels, and other logic cannot re-establish the power supply path between the NAND normal operating power supply and each VCC_i. After shutting off the normal power supply isolation switch, the controller keeps all destruction MOS branches off and enters the negative voltage generation preparation state. Before the residual voltage of VCC_i of each NAND is higher than the residual voltage threshold, the controller does not output a conduction enable signal to any destruction MOS branch. The normal power supply disabled state refers to the state in which the controller has shut off the normal power supply isolation switch between the NAND normal operating power supply and the VCC_i of each NAND, and prohibits the SSD host interface, NAND read / write channels, and other logic from re-establishing the power supply path between the normal operating power supply and each VCC_i.
[0028] The controller sequentially detects the residual voltage between VCC_i and GND for each NAND flash memory using the VCC_i residual voltage detection unit. The residual voltage threshold V... th Determine as follows: The controller reads the highest permissible residual voltage V before negative pressure injection. lim NAND normal operating voltage V n Fixed proportional step size Δλ, upper voltage divider resistor R up Lower voltage divider resistor R down Detection magnification G det Analog-to-digital converter reference voltage V ref The number of bits for analog-to-digital conversion (B) and the preset valid discrimination count (N) cnt The controller first determines whether the above parameters are valid, where V lim >0, V n >0, Δλ>0, R up >0, R down >0, G det >0, V ref >0, B is an integer greater than 1, N cnt The value must be an integer not less than 2; when any parameter is invalid, the controller invokes the preset emergency residual voltage threshold V. pre As the residual voltage threshold V th When all the above parameters are valid, the controller will determine the value based on V. lim / V n Calculate the residual voltage proportional parameter λ with a fixed proportional step size Δλ res , λ res =floor((V lim / V n() / Δλ)×Δλ; when the calculated λ res When the value is not greater than 0, the controller will select the candidate threshold V. cand Let V be the value of V. lim And record insufficient scaling resolution; when λ res When the value is greater than 0, the controller calculates the candidate threshold V. cand =min(V lim , λ res ×V n ).
[0029] The voltage division ratio β of the VCC_i residual voltage detection unit res According to β res =R down / (R up +R down ) Determined. Since the aforementioned parameter verification already requires R... up >0 and R down >0, R up +R down It is a positive value. The controller determines this based on β. res G det V ref And calculate the voltage resolution ΔV corresponding to the VCC_i terminal in the B calculation. res =V ref / [(2^B-1)×β res ×G det [and determine the minimum discriminable voltage V] min =N cnt ×ΔV res If V min Not higher than V cand Then V th Let V be the value of V. cand If V min Higher than V cand Then V th Let V be the value of V. min It also records any abnormalities in residual voltage detection resolution. A preset emergency residual voltage threshold V is used. pre Write this value during the factory, deployment, or security initialization phases; its value should not exceed V. lim When V lim When unavailable, V pre According to the normal operating voltage of NAND V n The preset ratio λ pre Determined, i.e., V pre =λ pre ×V n , where λ pre For the pre-written residual voltage emergency ratio, and λ pre Less than 1; when V nWhen this is also unavailable, a fixed residual voltage threshold written by a hardware coding network is used as V. pre .
[0030] Once the residual VCC_i voltage of each NAND flash memory is no higher than the residual voltage threshold, the controller outputs a power enable signal to the negative voltage generation module, activating it. The negative voltage generation module includes an inverting converter unit, a negative voltage output energy storage unit, and a negative voltage feedback sampling channel. The inverting converter unit receives low-voltage power from the SSD board and generates a negative voltage output relative to GND at the negative voltage output energy storage unit through a switching conversion method. The negative voltage feedback sampling channel acquires the common negative voltage output node voltage VNEG and feeds it back to the controller. The common negative voltage output node refers to the common negative potential connection node between the negative voltage output terminal of the negative voltage generation module and the input terminal of each NAND flash memory MOS branch, used to provide a negative injection voltage to the selected NAND flash memory MOS branch.
[0031] Effective threshold of negative pressure V th1 Determine as follows: The controller reads the target negative pressure amplitude A. neg The negative pressure generation module outputs a ripple ratio ρ rip Negative pressure feedback sampling error ratio ρ fb And negative pressure safety margin ratio ρ safe and the ratio of minimum negative pressure amplitude η min A neg >0, ρ rip ≥0, ρ fb ≥0, ρ safe ≥0, 0<η min <1. The controller calculates the candidate effective proportion η. calc =1-ρ rip -ρ fb -ρ safe . When A neg Effective and η min ≤η calc When η < 1, the controller will calc As an effective proportion η neg And determine the effective threshold V of negative pressure. th1 =-η neg ×A neg ; when A neg Zero, missing, or check failed, or η calc Less than η min , or η calc When the value is not less than 1, the controller does not use V. th1 And invoke the preset emergency negative pressure effective threshold V npre Preset emergency negative pressure effective threshold V npre According to the target negative pressure emergency amplitude A pre and emergency effective ratio ηpre Determined, i.e., V npre =-η pre ×A pre A pre and η pre All are written during the factory, deployment, or security initialization phases, and 0 < η pre <1.
[0032] The controller determines the current effective negative pressure threshold V based on the current parameter status. act ; when A neg and η neg When both are valid, V act Let V be the value of V. th1 When V th1 Unattainable and V npre When effective, V act Let V be the value of V. npre When V th1 and V npre If neither of these conditions is met, the controller will not proceed with the negative pressure injection process and will output a result indicating that the negative pressure threshold is unavailable. The controller detects that the common negative pressure output node voltage VNEG ≤ V. act At that time, the common negative voltage output node is determined to be in an injectable state. Before the common negative voltage output node becomes effective, all NAND destroy MOS branches remain off. In one specific implementation, the target negative voltage amplitude A neg 12V, effective ratio η neg If the value is 0.9, then the effective threshold V for negative pressure is... th1 It is -10.8V.
[0033] After the common negative voltage output node becomes valid, the controller performs chip-by-chip processing. The controller sets the current processing target as the i-th NAND chip according to a preset sequence and outputs an enable signal only to the destroy MOS branch corresponding to the i-th NAND chip, while keeping the destroy MOS branches corresponding to other NAND chips off. When impedance detection is required, the controller only activates the impedance detection branch corresponding to the i-th NAND chip, keeping the detection branches of other NAND chips off. Therefore, the common negative voltage output node only connects to the VCC_i of the i-th NAND chip through the currently selected destroy MOS branch, avoiding simultaneous access to the negative voltage output for multiple NAND chips. After the i-th NAND chip completes the injection, detection, or processing result recording, the controller shuts off the destroy MOS branch corresponding to the i-th NAND chip and switches the processing target to the next NAND chip.
[0034] Before performing negative voltage injection on the i-th NAND chip, the controller acquires the VCC-GND equivalent impedance reference of the i-th NAND chip before injection. This VCC-GND equivalent impedance reference is used to record the initial electrical parameter state between the power supply terminal and the ground terminal of the NAND chip before negative voltage injection, and serves as a comparison benchmark for judging impedance changes after injection, avoiding the influence of individual chip differences due to relying solely on a single impedance value after injection. Specifically, the controller shuts down the destruction MOS branch of the i-th NAND chip and only turns on the impedance detection branch of the i-th NAND chip; the impedance detection unit includes a detection current source, a detection current limiting resistor, a detection gating switch, and a voltage sampling channel.
[0035] Detection allowable voltage threshold V allow Determine as follows: V allow =min(V dlim V off ), where V dlim The upper limit of the sensing voltage that the impedance sensing unit is allowed to apply between VCC_i and GND is V off This is the upper limit of the non-on voltage of the NAND internal protection structure. V dlim The range of the impedance detection unit is determined by the output range of the current source, the range of the voltage sampling channel, and the input range of the analog-to-digital converter; V off The non-conducting parameters of the protection structure corresponding to the NAND model are written into the NAND protection parameter table. If V dlim or V off If the voltage is unavailable, fails verification, or is not greater than zero, the controller invokes the preset emergency detection allowable voltage threshold V. dpre As V allow Detection current I det Determine as follows: The controller reads the upper limit of the detection voltage V. dlim Detection of allowable voltage threshold V allow Detection impedance lower limit Z min and the upper limit of non-conducting current I of NAND protection structure poff When Z min >0, V dlim >0, V allow >0 and I poff When I > 0, the controller calculates the upper limit of the detection current I. lim =min(V dlim / Z min V allow / Z min I poff ), and according to the detection current resolution ΔI det Rounding down gives I det =floor(I lim / ΔI det )×ΔI detWhen Z min If the value is zero, missing, or the check fails, V is not executed. dlim / Z min and V allow / Z min Calculate and call the preset emergency detection current I dpre Preset emergency detection current I dpre Preset emergency detection impedance lower limit Z min1 and the upper limit of non-conducting current I of the preset emergency protection structure poff1 Write during the factory, deployment, or security initialization phase, and satisfy I dpre ×Z min1 Not exceeding the preset emergency detection allowable voltage threshold V dpre , and I dpre Emergency value I not exceeding the upper limit of the non-conducting current of the NAND protection structure poff1 .
[0036] The controller acquires the detection response voltage V of VCC_i to GND. prei And based on the detected current I det Calculate the equivalent impedance Z of VCC-GND before injection. prei .
[0037] The equivalent impedance Z of VCC-GND before injection of the i-th NAND flash memory chip prei Determine as follows:
[0038] Z prei =|V prei | / I det ;
[0039] Among them, V prei VCC_i represents the response voltage to GND of the i-th NAND flash memory chip before injection, in volts; det This is a low-amplitude detection current, measured in amperes; Z prei The equivalent impedance from VCC to GND before injection is in ohms. The controller calculates Z... prei Pre-judgment I det Is it greater than zero; when I det If the value is zero, missing, or the check fails, |V is not executed. prei | / I det Calculate and record the impedance reference anomaly of the i-th NAND chip.
[0040] The controller will Z prei With the initial short-circuit threshold Z th Compare the initial short-circuit threshold Z. th Determine as follows: The controller reads the detectable minimum VCC-GND equivalent impedance Z. min Upper limit of the on-resistance error R of the detection channelonerr and impedance detection error margin Z margin Calculate Z th =Z min +R onerr +Z margin Z min R onerr and Z margin All data are read from the short-circuit judgment parameter table, which is categorized by NAND model and detection current I. det The upper limit of the detection selector switch's on-resistance, the upper limit of the detection line resistance, and the upper limit of the voltage sampling error are written into the corresponding parameters. When Z min R onerr or Z margin If the value cannot be obtained or the verification fails, the controller invokes the preset emergency initial short-circuit threshold Z. th1 As Z th Preset emergency initial short-circuit threshold Z th1 Write during the factory, deployment, or security initialization phase that the error margin is not less than the sum of the preset minimum detectable VCC-GND equivalent impedance, the maximum on-resistance error of the detection channel, and the maximum impedance detection error margin. When Z prei Not higher than Z th At that time, the controller determines that the i-th NAND flash memory chip already had an initial short circuit anomaly between VCC and GND before the negative pressure injection, and no longer sends Z... prei As an equivalent impedance reference before effective injection; when Z prei Higher than Z th At that time, the controller will Z prei Used as the equivalent impedance reference for VCC-GND before injection of the i-th NAND chip.
[0041] After obtaining the equivalent impedance of VCC-GND before injection, the controller disconnects the impedance detection branch of the i-th NAND chip and turns on the corresponding destruction MOS branch of the i-th NAND chip. The common negative voltage output node is connected to VCC_i of the i-th NAND chip through this destruction MOS branch, and GND of the i-th NAND chip remains grounded. This creates a negative injection voltage between VCC_i and GND of the i-th NAND chip, where the VCC_i potential is lower than the GND potential, and generates a negative injection current through the internal structure related to VCC_i-GND. This negative injection current acts on the internal power rail related structures, ESD protection structures, or parasitic conduction paths of the NAND chip.
[0042] The controller during a single injection duration T inj The MOS branch of the i-th NAND flash memory is kept on during destruction. Single injection duration T inj Determine as follows: The controller reads the target negative pressure amplitude A. neg The target injected charge Q corresponding to the NAND model injreqThe conservative injection current lower limit I of the negative pressure injection path injmin Destroy the current limiting capability of the MOS branch I injlim Minimum injection duration T injmin Maximum allowed time T for a single chip max And the controller timing resolution Δt. Where, I injmin The guaranteed injection current lower limit is determined based on the target negative voltage amplitude, the upper limit of the on-resistance of the destroyed MOS branch, the sampling resistor value, the equivalent impedance range of the NAND power supply terminal, and the output capability of the negative voltage generation module, and I injmin Not greater than I injlim .
[0043] If I injmin >0, Q injreq >0, Δt>0, and T max Not less than T injmin Then the controller calculates the candidate injection duration T. injcand =Q injreq / I injmin T is obtained by rounding up according to the timing resolution. injcalc =ceil(T injcand / Δt)×Δt; then determine T. inj =min(T max ,max(T injmin T injcalc )). If I injmin If the value is zero, missing, or the check fails, Q will not be executed. injreq / I injmin Calculate and call the preset emergency single injection duration Ti njpre Preset emergency single injection duration T injpre Write during the factory, deployment, or security initialization phase, and satisfy T injmin ≤T injpre ≤T max The duration of a single injection is limited by the controller's hardware timer. Once the hardware timer expires, the multi-channel MOS control circuit shuts down the currently destroyed MOS branch, regardless of whether the software process is complete.
[0044] Within a single injection duration, the current sampling unit collects the injection current of the destroyed MOS branch of the i-th NAND chip according to a preset sampling period, obtaining the injection current timing data C of the i-th NAND chip in the k-th injection. I (i, k), where the injection current at the j-th sampling point is denoted as I. ik (j). Injection current timing data C I(i, k) is used to calculate current surges, identify rapid conduction or ablation changes during the injection process, and trigger hardware overcurrent protection. k starts counting from 1; if the electrical parameter failure criterion is reached after the first injection of the i-th NAND chip, a second injection will not occur; k is incremented and supplementary injection is triggered only if the i-th NAND chip has not reached the electrical parameter failure criterion and has not exceeded the maximum number of injections per chip. The current sampling unit can be implemented using a series sampling resistor, a differential amplifier, and an analog-to-digital conversion channel; when a common current sampling resistor is used, since only one destroyed MOS branch is allowed to conduct at any given time, the common current sampling value is used as the injection current sampling value of the currently selected NAND chip.
[0045] To reduce the impact of single-point noise, the controller will inject current timing data C. I (i, k) is divided into multiple sampling windows, and the average current of each sampling window is calculated. The current surge ΔI in the i-th NAND flash during the k-th injection is given. ik Determine as follows:
[0046] ΔI ik =max|Q ik (m)-Q ik (m-1)|;
[0047] Among them, Q ik (m) is C I Each sampling point I in the m-th sampling window of (i, k) ik The average value of (j), in amperes; Q ik (m-1) represents the sampling points I within the adjacent previous sampling window. ik (j) is the average value in amperes; max is the maximum value taken over all adjacent sampling windows in the k-th injection; ΔI ik This represents the maximum current change between adjacent sampling windows, measured in amperes. This current surge is used to identify rapid conduction, ablation, or breakage changes in the internal conduction path of a NAND flash memory under negative electrical stress.
[0048] After the k-th single injection, the controller shuts off the destruction MOS branch of the i-th NAND flash memory chip, temporarily disconnecting the common negative voltage output node from the VCC_i of the i-th NAND flash memory chip. Subsequently, the controller re-energizes the impedance detection branch of the i-th NAND flash memory chip, using the same detection current I as before the injection. det Detect the response voltage V after VCC_i injects into GND. ik The equivalent impedance Z of VCC-GND after injection is obtained. ik The detection current, detection direction, sampling window, and conversion rules used in post-injection detection remain consistent with those used in pre-injection detection.
[0049] The VCC-GND impedance change ΔZ of the i-th NAND flash after the k-th injection. ik Determine as follows:
[0050] ΔZ ik =|Z ik -Z prei |;
[0051] Among them, Z ik Z represents the equivalent impedance of the i-th NAND flash memory chip after the k-th injection, in ohms; prei The reference value for the equivalent impedance of VCC-GND before injection of this NAND flash memory is obtained before negative pressure injection, in ohms; ΔZ ik This represents the impedance change relative to the pre-implantation impedance reference, in ohms. Z is not reset during supplementary implantation. prei The impedance mutation after each subsequent injection is still compared with the impedance reference before the injection, thus reflecting the cumulative electrical parameter changes of the NAND chip since it entered the destruction process. ΔZ ik This indicates the degree of continuous change in the VCC-GND electrical parameters of the NAND flash memory chip after negative voltage injection relative to the pre-injection reference, and is used together with the current surge to determine whether the NAND flash memory chip has reached the electrical parameter failure criterion. In this embodiment, the physical failure of the current NAND flash memory is confirmed by the controller based on reaching the electrical parameter failure criterion. Reaching the electrical parameter failure criterion means that the current NAND flash memory chip experiences a surge in injection current that meets the threshold requirement during the negative voltage injection process, and that its VCC-GND equivalent impedance undergoes a continuous change relative to the pre-injection equivalent impedance reference that meets the threshold requirement after negative voltage injection. This state indicates that the power rail, protection structure, or parasitic conduction path of the current NAND flash memory chip has undergone a failure change that can be confirmed by external electrical parameter detection, and the controller confirms that the current NAND flash memory chip has completed the negative voltage physical destruction process.
[0052] The controller determines whether the i-th NAND flash memory chip has reached the electrical parameter failure criterion based on both the injection current surge and the VCC-GND impedance surge. The electrical parameter failure criterion includes a current surge criterion and an impedance surge criterion. The current surge criterion is: from the first injection to the current k-th injection, the current surge of any injection in the i-th NAND flash memory chip reaches the current surge threshold; the impedance surge criterion is: the VCC-GND impedance surge after the current k-th injection reaches the impedance surge threshold, i.e., ΔZ. ik ≥ΔZ th1 When both the current surge criterion and the impedance surge criterion are met, the controller determines that the i-th NAND has reached the electrical parameter failure criterion, and uses this determination result as a confirmation condition that the i-th NAND has completed the negative pressure physical destruction process, and records the processing result of the i-th NAND as having completed the negative pressure physical destruction process.
[0053] Current sudden change threshold ΔI th The current sampling unit is determined as follows: R is a sampling resistor. sense Sampling magnification factor G cur And the analog-to-digital converter, the controller calls the analog-to-digital converter reference voltage V from the parameter storage unit. refcur Modular-to-digital conversion bit depth B cur Sampling window length N win , Current effective mutation ratio β I Preset noise counting margin N noise and hardware overcurrent threshold I octh Among them, V refcur B cur R sense and G cur Determined by the hardware specifications or factory calibration parameters of the current sampling unit; N win Determined based on the current sampling period and the preset sampling window duration; N noise Determined based on the quantization noise, amplifier noise, and factory-calibrated noise margin of the current sampling unit; β I The effective current mutation ratio pre-written into the parameter storage unit; I octh The hardware overcurrent threshold is determined based on the rated current of the destroyed MOS branch, the current limit value of the negative voltage generation module, and the allowable power of the sampling resistor.
[0054] The controller performs validity checks on the parameters involved in the calculation. The validation conditions include: when R sense >0, G cur >0, V refcur >0, B cur N is an integer greater than 1 win >0 and I octh When the value is greater than 0, all participating parameters are deemed valid, and the controller calculates the current resolution ΔI corresponding to a single analog-to-digital conversion count. adc =V refcur / [(2^B cur -1)×G cur ×R sense ], and calculate the upper limit of current sampling noise ΔI. noise =N noise ×ΔI adc / √N win Subsequently, the threshold for the sudden change in current, ΔI, was determined. th =max(ΔI noise ,β I ×I octh When (2^B) cur -1)×G cur ×R sense zero, N win Zero, Iocth If the parameter is unavailable or any parameter verification fails, the controller will not perform the corresponding division calculation and will instead call the preset emergency current surge threshold ΔI. pre As the threshold for sudden current change ΔI th Preset emergency current surge threshold ΔI pre Write during the factory, deployment, or security initialization phase, and the noise current should not be lower than the upper limit of the current sampling unit under maximum noise conditions.
[0055] Impedance mutation threshold Δ Zth1 The following method is used to determine the current sensing I from the parameter storage unit: det Detection response voltage error upper limit ΔV det Upper limit of the on-resistance error R of the selected path patherr β, effective impedance change ratio Z and the preset emergency impedance change threshold ΔZ pre Wherein, ΔV de t and R patherr The factory calibration parameters, device specifications, or self-test results of the impedance detection unit are written into the parameter storage unit, β. Z Write it from the impedance change determination parameter table.
[0056] When I det >0, and Z prei To effectively inject the equivalent impedance reference VCC-GND, the controller calculates the upper limit of impedance detection error ΔZ based on the upper limit of the detection response voltage error and the detection current. err =(ΔV det / I de t)+R patherr And determine the impedance change threshold ΔZ th1 =max(ΔZ err ,β Z ×Z prei When ΔV det R patherr or β Z Unattainable but Z prei Effective, and with a preset emergency impedance change threshold ΔZ pre When effective, the controller will ΔZ pre As the impedance sudden change threshold ΔZ th1 Preset emergency impedance change threshold ΔZ pre Write during the factory, deployment, or security initialization phase, and the impedance error shall not be lower than the upper limit of the impedance detection unit under the conditions of maximum voltage sampling error, maximum detection current error, and maximum selection path on-resistance error. When I det Zero, missing, or check failed, or Z prei When the effective pre-injection VCC-GND equivalent impedance reference is not used, the controller does not calculate ΔZ.th1 The impedance mutation criterion is not executed, and the i-th NAND chip is recorded as having an impedance reference anomaly.
[0057] The current injection count of the i-th NAND chip is denoted as k, with k counting from 1. The maximum injection count for a single chip is K. max This is used to limit the total number of injections allowed in the current round of processing for the i-th NAND chip, where 1 ≤ k ≤ K. max When the current surge of the i-th NAND flash memory does not reach the current surge threshold ΔI... th Or the impedance change in VCC-GND did not reach the impedance change threshold ΔZ. th1 And the current number of injections k is less than the maximum number of injections per chip K. max When the time comes, the controller updates the current injection count to k+1 and returns to the negative pressure injection step, adding one negative pressure injection to the i-th NAND chip.
[0058] Maximum number of injections per chip K max Determined as follows: The controller reads the maximum permissible total negative pressure injection time T of a single chip. max1 Duration T of a single injection inj and preset maximum number of injections per emergency unit K maxpre When T max1 >0 and T inj When K > 0, the controller calculates K. max =floor(T max1 / T inj ), and make K max Not less than 1; when T inj If the value is zero, missing, or the check fails, T is not executed. max1 / T inj Calculate and call the preset maximum number of emergency single-chip injections K. maxpre As K max K maxpre Write during the factory, deployment, or security initialization phase, and satisfy K maxpre ×T injpre The total duration of negative pressure injection per unit should not exceed T. max1 Before the additional injection, the controller reconfirms that the voltage of the common negative voltage output node still reaches the current effective negative voltage threshold, and that all NAND destruction MOS branches except for the current i-th NAND are in the off state.
[0059] Before the additional injection, the controller reconfirms that the voltage of the common negative voltage output node still reaches the effective negative voltage threshold, and that all NAND destruction MOS branches except for the current i-th NAND are in the off state.
[0060] When the current surge of the i-th NAND flash memory does not reach the current surge threshold ΔI thOr the impedance change in VCC-GND did not reach the impedance change threshold ΔZ. th1 When the number of injection operations performed on the i-th NAND flash memory reaches the maximum number of injection operations Kmax for a single chip, the controller shuts off the destruction MOS branch of the i-th NAND flash memory, maintains the normal power supply isolation state of the i-th NAND flash memory, and records the i-th NAND flash memory as a processing state that has not reached the upper limit. This state indicates that the i-th NAND flash memory has completed this round of processing, but has not been confirmed by the controller to have completed the negative voltage physical destruction process. Therefore, the i-th NAND flash memory is marked as a processed abnormal chip. When the global locking condition is not triggered, the controller switches to the next NAND flash memory according to the chip-by-chip abnormal processing strategy.
[0061] In this embodiment, the chip-by-chip anomaly handling strategy refers to the following: when the current NAND experiences an unmet upper limit processing state, impedance reference anomaly, initial short circuit anomaly, negative voltage injection anomaly, sampling saturation anomaly, or overcurrent processing result, and the global lockout condition is not triggered, the controller records the current NAND's anomaly state, maintains the normal power supply isolation of the NAND and destroys the MOS branch shutdown, marks the NAND as a processed anomaly chip, and then switches the processing target to the next NAND chip.
[0062] After the i-th NAND flash memory is processed, the controller determines whether there are still unprocessed NAND flash memory chips. If there are unprocessed NAND flash memory chips, the controller updates i to the number of the next NAND flash memory chip and returns to the pre-injection impedance detection step. After all NAND flash memory chips have been processed, the controller shuts down the negative voltage generation module and turns on the common negative voltage output node release unit, so that the common negative voltage output node is released to a safe potential close to GND through the bleed resistor or the controlled bleed switch.
[0063] After all NAND flash memory chips have been processed, the controller keeps all normal power supply isolation switches off and all destroyed MOS branches off, and outputs the power-off isolation status after all NAND flash memory chips have been processed. In this state, the normal operating power supply of the NAND flash memory chips is no longer connected to the VCC_i of each NAND flash memory chip, and the common negative voltage output node is no longer connected to the VCC_i of each NAND flash memory chip. The controller retains records of the processing results, injection counts, current surges, and impedance surges of each NAND flash memory chip. The controller generates an overall processing result based on the processing results of each NAND flash memory chip. When the processing results of all NAND flash memory chips are all confirmed as having completed negative voltage physical destruction, the overall processing result is marked as "all destroyed" indicating that all NAND flash memory chips have been confirmed by the controller to have completed negative voltage physical destruction. When there are processing states that do not meet the upper limit, impedance reference abnormalities, initial short circuit abnormalities, negative voltage injection abnormalities, sampling saturation abnormalities that do not obtain effective current surges, or overcurrent processing results, the overall processing result is marked as "abnormal chips exist," indicating that at least one NAND flash memory chip has completed this round of processing but has not been confirmed by the controller to have completed negative voltage physical destruction.
[0064] Through the above process, the destruction circuit first isolates the normal power supply of the NAND, then generates a negative voltage from the low-voltage power supply on the SSD board, and pulls the VCC_i of the NAND to a negative voltage state lower than GND on a chip-by-chip basis; the negative injection current is constrained within the VCC-GND path of the currently selected NAND, and whether to supplement injection is determined by the sudden change in the injection current and the sudden change in the VCC-GND impedance before and after injection, so that the damage differences caused by the internal ESD protection structure, parasitic conduction path or power rail differences of different NANDs can be closed-loop processed by chip-by-chip supplementary injection.
[0065] Example 2: Building upon the chip-by-chip negative voltage injection destruction process in Example 1, this example further illustrates the possible abnormal branches in the destruction process and their corresponding boundary handling methods. Example 1 mainly describes the main process when the trigger is valid, power supply isolation is complete, residual voltage meets the standard, the common negative voltage output node is valid, and the chip-by-chip injection process is executed normally. This example, however, addresses situations such as trigger confirmation failure, residual voltage not meeting the standard, common negative voltage output node not meeting the standard, impedance reference abnormality, injection process abnormality, sampling abnormality, overcurrent abnormality, and parameter abnormality. It explains how the controller distinguishes between single-chip abnormalities and global abnormalities, and executes processing logic such as continuing processing, stopping injection, shutting down branches, or releasing the common negative voltage output node according to the abnormality type. To avoid the loss of processing status due to power failure and subsequent power restoration during the destruction process, the controller writes the destruction process status into the abnormal status record area of the parameter storage unit after the destruction enable signal is determined to be valid. The abnormal status recording area records at least the following: the valid flag of the destruction process, the currently processed NAND number, the current injection count, the interrupt recovery count, the processed NAND flag, the abnormal chip flag, the current process stage, the most recently recorded common negative voltage output node status, the most recently recorded current destroyed MOS branch status, the VCC-GND equivalent impedance reference before injection, the valid injection completion flag, the current surge corresponding to the current injection, the valid injection current data flag, and the status verification value. The current process stage includes power supply isolation completion, residual voltage detection completion, negative voltage establishment completion, impedance detection before injection completion, negative voltage injection in progress, impedance detection after injection in progress, single-chip processing completion, and global abnormal lockout. The controller updates the abnormal status recording area each time it switches process stages, turns on or off the destroyed MOS branch, completes single-chip processing result recording, and triggers abnormal handling. Specifically, the valid flag of the destruction process is written after the destruction enable signal is determined to be valid; when all NANDs have completed chip-by-chip processing and generated the overall processing result, the controller updates the valid flag of the destruction process to the destruction completion flag; when the global lockout condition is triggered, the controller updates the valid flag of the destruction process to the global lockout flag.
[0066] The status check value is used to verify the integrity and consistency of each field in the abnormal status record area before and after a power outage. The status check value is generated as follows: The controller reads all fields in the abnormal status record area except the status check value according to a preset field order, concatenates each field sequentially according to a fixed byte length to form status record data, and performs a cyclic redundancy check (CRC) calculation on the status record data to obtain the status check value. Each time the abnormal status record area is updated, the controller regenerates and writes the status check value. After power-on, the controller recalculates the check result according to the same field order and the same calculation rules. The check polynomial, initial value, input byte order, and XOR value used in the CRC calculation are pre-written into the parameter storage unit. If the recalculated check result matches the status check value stored in the abnormal status record area, the status check value is considered valid; if they do not match, the status check value is missing, or any field involved in the check is missing, the status check value is considered invalid.
[0067] When the destruction enable signal is not continuously maintained until the preset trigger confirmation time, the controller will not enter the destruction process, the normal power supply isolating switch will remain in its original normal working state, the negative voltage generation module will not start, and all destruction MOS branches will remain off.
[0068] When a power outage occurs and power is restored during the destruction process, the controller first reads the abnormal status record area during the initialization phase. If the abnormal status record area does not contain a valid destruction process flag and the normal power supply prohibition state is not in effect, the controller will process the process as if it has not entered the destruction process state, and all destruction MOS branches will remain off. If the abnormal status record area contains a record but the status verification value is invalid, or the normal power supply prohibition state is in effect but the current processing stage cannot be confirmed, the controller will keep all destruction MOS branches off, prohibit the normal NAND power supply from reconnecting to the VCC_i of each NAND, and trigger the global lock condition. If the abnormal status record area shows that the valid destruction process flag has been updated to the destruction completion flag, the controller will not resume the chip-by-chip injection process, will keep all destruction MOS branches off, and will output the destruction completion status. If the abnormal status record area shows that the valid destruction process flag has been updated to the global lock flag, the controller will keep all destruction MOS branches off, prohibit the normal NAND power supply from reconnecting to the VCC_i of each NAND, and maintain the global lock state. If the abnormal status record area contains a valid destruction process flag, and the record shows that there are still unprocessed NANDs or NANDs with unconfirmed processing results, the controller will determine that a destruction interruption restart event has occurred, increment the interrupt recovery count, and regenerate the status verification value. When the number of interrupt recovery attempts reaches the preset upper limit, the controller will no longer resume chip-by-chip processing and will trigger a global lock condition. The preset upper limit of interrupt recovery attempts is written to the parameter storage unit during the factory, deployment, or security initialization phase.
[0069] After a destruction interruption restart event occurs, the controller keeps all destroyed MOS branches off, prevents the normal operating power supply of the NAND from being reconnected to the VCC_i of each NAND, and monitors the voltage of the common negative voltage output node and the residual VCC_i voltage of each NAND. If the voltage of the common negative voltage output node does not reach the common node safe voltage threshold, or if the residual VCC_i voltage of any NAND exceeds the residual voltage threshold V, the controller will take action. th When the controller first activates the corresponding release branch to release the charge, and the voltage of the common negative voltage output node reaches the common node safety voltage threshold, and the residual voltage of VCC_i of each NAND is not higher than the residual voltage threshold V, the controller will then release the charge. th At this point, it is determined that the VCC_i of the common negative voltage output node and each NAND flash memory has reached a safe potential. Before reaching the safe potential, the controller prevents any destroyed MOS branch from conducting.
[0070] If the abnormal status recording area shows that negative voltage injection was in progress before the power outage, the controller will record this interrupted injection as invalid, will not count this injection as a valid injection, and will not use the injection current timing data that was not fully collected before the power outage as the current change criterion. The controller retains the VCC-GND equivalent impedance reference written before the power outage, and will re-execute this negative voltage injection for the NAND after the residual voltage safety condition and the common negative voltage output node effective condition are met again. If the VCC-GND equivalent impedance reference before the power outage does not exist or the status verification is invalid, the controller records the NAND as having an impedance reference abnormality and handles it according to the chip-by-chip abnormality handling strategy.
[0071] If the abnormal status recording area shows that the NAND was in the process of post-injection impedance detection or the single-chip processing result was not written before the power failure, the controller will re-perform post-injection VCC-GND impedance detection on the current NAND and determine the processing result of the NAND based on the saved pre-injection VCC-GND equivalent impedance reference, the newly obtained post-injection equivalent impedance, the current mutation amount corresponding to the current injection, and the injection current data validity flag. If the injection current data validity flag is invalid, or the current mutation amount corresponding to the current injection cannot be obtained, the NAND will be recorded as an interrupted abnormal chip that has not obtained a valid current mutation amount, and processed according to the chip-by-chip abnormality handling strategy.
[0072] When the controller confirms that some NAND flash memory has been marked as processed based on the abnormal state recording area, it will not repeat the negative voltage injection on the processed NAND flash memory after restarting and recovering. When it is confirmed that there are still unprocessed NAND flash memory, the controller will continue to process each NAND flash memory from the current NAND flash memory or the next unprocessed NAND flash memory recorded in the abnormal state recording area. If the abnormal state recording area verification fails, the current processing object cannot be confirmed, the common negative voltage output node cannot be released to a safe potential, or the residual voltage of VCC_i of any NAND flash memory cannot be released below the residual voltage threshold, the controller will trigger a global lockout condition, shut down the negative voltage generation module, shut down all destruction MOS branches, release the charge of the common negative voltage output node, and output the destruction interrupt restart abnormal handling result.
[0073] Preset residual release time T res Determine as follows: The controller reads the equivalent capacitance C of node VCC_i. i The discharge resistor R in the residual release branch of VCC_i reli The residual voltage ratio before release is α, which is the target value. res and controller timing resolution Δt res C i >0, R reli >0, 0<α res <1, Δt res >0. When all the above parameters are valid, the controller calculates the release margin coefficient μ=-ln(α) res ), and calculate T res =ceil((μ×R reli ×C i ) / Δt res )×Δt res When C i R reli or Δt res Zero, missing, or check failed, or α res If the value is not between 0 and 1, the calculation is not performed, and the preset emergency residual release time T is invoked. respre T respre The time written during the factory, deployment, or security initialization phase shall not be less than the release time calculated using the equivalent capacitance of the maximum VCC_i node and the maximum residual release branch resistance. If a controlled discharge switch is provided, the controller shall periodically turn on the controlled discharge switch to continue releasing the residual charge of VCC_i; if the residual voltage still cannot be reduced below the residual voltage threshold, the controller shall stop the negative pressure injection process.
[0074] When the negative pressure generation module starts up and the common negative pressure output node fails to reach the effective negative pressure threshold within the preset negative pressure establishment time, the controller shuts down the negative pressure generation module, prohibits the conduction of any destroyed MOS branch, and outputs the processing result of the common negative pressure output node failing to meet the standard. Preset negative pressure establishment time T neg Determine as follows: The controller reads the equivalent capacitance C of the common negative voltage output node. neg Target negative pressure amplitude A neg Current limiting value I of negative pressure generation module neglim Negative pressure generation module startup delay T start and controller timing resolution Δt neg C neg >0, A neg >0, I neglim >0, T start ≥0, Δt neg >0. When all the above parameters are valid, the controller calculates T. negcand =(ξ×C neg ×A neg / I neglim )+T start And determine T neg =ceil(T negcand / Δt neg )×Δt neg , where ξ is the negative pressure margin coefficient. If I neglim If the value is zero, missing, or the check fails, then C will not be executed. neg ×A neg / I neglim Calculate and call the preset emergency negative pressure establishment time T negpre T negpre The time to be written during the factory, deployment, or security initialization phase shall not be less than the setup time calculated using the maximum equivalent capacitance of the common negative pressure output node, the target negative pressure emergency amplitude, and the minimum current limit of the negative pressure generation module.
[0075] If the equivalent impedance of VCC-GND before injection for the i-th NAND flash memory cannot be obtained, or if the equivalent impedance of VCC-GND before injection does not meet the valid reference condition, the controller will not determine that the NAND flash memory has reached the electrical parameter failure criterion. If the detection channel is open-circuited, the detection current source is faulty, or the sampling channel is saturated, making it impossible to calculate the equivalent impedance Z of VCC-GND before injection, the controller will not accept this NAND flash memory. prei If the controller shuts down the detection branch and destroys the MOS branch of that NAND chip, records the i-th NAND chip as having an impedance reference abnormality, and maintains normal power supply isolation for that NAND chip. If Z can be calculated... prei But Z prei Not higher than the initial short-circuit threshold Z thIf the controller determines that the i-th NAND flash memory chip already had an initial short-circuit anomaly between VCC and GND before the negative voltage injection, it records the i-th NAND flash memory chip as having an initial short-circuit anomaly and maintains its normal power supply isolation without connecting it to a common negative voltage output node. Impedance reference anomalies or initial short-circuit anomalies are not marked as having completed the negative voltage physical destruction process and are output as an abnormal chip in the final overall processing result. When an impedance reference anomaly or initial short-circuit anomaly does not trigger the global locking condition, the controller continues processing the next NAND flash memory chip according to the chip-by-chip anomaly handling strategy.
[0076] When the actual negative voltage amplitude Aneg_meas corresponding to the common negative voltage output node voltage VNEG exceeds the current effective negative voltage amplitude range during the injection process, the controller determines that the common negative voltage output node is abnormal; where A negmeas =|VNEG|, the current effective negative pressure amplitude range is determined by the negative pressure lower limit amplitude A. neglow and negative pressure upper limit amplitude A neghigh Confirmed, A neglow =η low ×A neg A neghigh =η high ×A neg ηlow is the effective lower limit ratio of negative pressure, η high This represents the effective upper limit ratio of negative pressure, and 0 < η. low <1<η high . When A negmeas <A neglow When A is in a negative voltage range, it indicates that the negative voltage amplitude of the common negative voltage output node is insufficient; when A... negmeas >A neghigh When this occurs, it indicates that the negative voltage amplitude of the common negative voltage output node is too large. In any of the above situations, the controller immediately shuts down the destruction MOS branch of the current i-th NAND chip, stops the current injection timing, and controls the negative voltage generation module to enter either the negative voltage recovery state or the overvoltage shutdown state, depending on the type of the anomaly. The negative voltage recovery state refers to the state where the negative voltage generation module maintains output regulation while all destruction MOS branches are shut down. The overvoltage shutdown state refers to the state where the negative voltage generation module stops output regulation, all destruction MOS branches remain shut down, and the charge of the common negative voltage output node is released through the common negative voltage output node release unit.
[0077] Preset recovery time T rec Determine as follows: The controller reads the equivalent capacitance C of the common negative voltage output node. neg Target negative pressure amplitude A neg The negative pressure generation module restores the current limiting value I. reclim and controller timing resolution Δt rec C neg >0, A neg >0, I reclim>0, Δt rec >0. When all the above parameters are valid, the controller calculates T. reccand =ζ×C neg ×A neg / I reclim And determine T rec =ceil(T reccand / Δt rec )×Δt rec , where ζ is the recovery margin coefficient. If I reclim If the value is zero, missing, or the check fails, then C will not be executed. neg ×A neg / I reclim Calculate and invoke the preset emergency recovery time T recpre T recpre The time written during the factory, deployment, or security initialization phase shall not be less than the recovery time calculated using the maximum equivalent capacitance of the common negative pressure output node, the target negative pressure emergency amplitude, and the minimum recovery current limit value of the negative pressure generation module.
[0078] If the common negative pressure output node is at T rec If the current effective negative pressure amplitude range is re-entered within the range, the controller will re-execute the injection; if the common negative pressure output node is in T... rec If the current effective negative voltage amplitude range is not yet reached, or if the negative voltage amplitude is too large, the controller records the current i-th NAND as a negative voltage injection anomaly, shuts down the negative voltage generation module, shuts down all destroyed MOS branches, releases the charge of the common negative voltage output node, and stops the negative voltage injection process of subsequent NANDs.
[0079] When the current sampling unit detects that the injected current exceeds the hardware overcurrent threshold I octh Upon that time, the multi-channel MOS control circuit immediately shuts down the currently destroyed MOS branch, the controller records the overcurrent handling result, and after confirming that the VCC_i to GND voltage of the i-th NAND chip has dropped to the detection allowable voltage range, performs VCC-GND impedance detection on the i-th NAND chip after injection. The detection allowable voltage range is determined by the detection allowable voltage threshold V. allow Confirmed. Hardware overcurrent threshold I. octh Determine as follows: The controller reads the rated current I of the destroyed MOS branch. rate Current limiting value I of negative pressure generation module neglim Sampling resistor allowable power P sensemax Sampling resistance value R sense and overcurrent safety margin factor κ oc , where I rate >0, I neglim >0, P sensemax >0, R sense >0, 0<κ oc<1. When all the above parameters are valid, the controller calculates I. octh =min(κ oc ×I rate κ oc ×I neglim sqrt(P sensemax / R sense If R sense If the value is zero, missing, or exceeds the preset allowed range, then P will not be executed. sensemax / R sense Calculate and invoke the preset emergency hardware overcurrent threshold I. ocpre I ocpre During factory, deployment, or security initialization phases, the current written value shall not exceed the minimum value among the rated current of the destroyed MOS branch, the current limit value of the negative voltage generation module, and the current corresponding to the allowable power of the sampling resistor; when I ocpre If the MOS branch is also unavailable, the controller will prevent the corresponding destroyed MOS branch from being turned on.
[0080] If the sampling channel of the current sampling unit becomes saturated, preventing the acquisition of a valid current surge, the controller immediately shuts down the destroyed MOS branch corresponding to the i-th NAND chip and marks the injected current curve as an invalid current curve, not to be used for the current surge criterion. The controller then performs VCC-GND impedance detection after injection and records the sampling saturation event. Since the controller cannot confirm whether the actual injected current is still within the allowable range when the sampling channel is saturated, the controller will not continue to add negative voltage injection to the NAND chip according to the normal supplementary injection process; when the NAND chip fails to simultaneously meet the current surge criterion and the impedance surge criterion, the controller records it as a sampling saturation anomaly due to failure to acquire a valid current surge and handles it according to the chip-by-chip anomaly handling strategy.
[0081] When a single-chip fault exists but the global lockout condition is not triggered, the controller continues processing the next NAND chip according to the chip-by-chip fault handling strategy. Single-chip faults include impedance reference faults, initial short-circuit faults, failure to meet upper limit processing status, sampling saturation faults without obtaining a valid current surge, interrupted fault chips, or overcurrent processing results. The global lockout condition is triggered when any of the following conditions are met: the common negative voltage output node reaches the preset negative voltage establishment time T. neg The effective negative pressure threshold V was not reached. th1 The common negative pressure output node recovers within the preset time T. rec The voltage does not re-enter the current effective negative voltage range, or the negative voltage amplitude is too large; the abnormal state record area verification fails, the current processing object cannot be confirmed, or the interruption recovery count reaches the preset interruption recovery count limit; the residual voltage of VCC_i of any NAND flash memory exceeds the preset residual release time T. res The voltage remains above the residual voltage threshold V. thOnce the global lock condition is triggered, the controller stops the subsequent NAND negative pressure injection process and outputs the corresponding global exception handling result.
[0082] Through the above-mentioned abnormal branching and boundary handling, the controller can distinguish between single-chip abnormalities and global abnormalities: For single-chip abnormalities, the controller records the abnormal chip result and continues to process the next NAND chip if the global locking condition is not triggered; for global abnormalities, the controller shuts down the negative voltage generation module, shuts down all destruction MOS branches, releases the charge of the common negative voltage output node, and maintains the power-off isolation state of all NAND chips, thereby avoiding the application of negative electrical stress to multiple NAND chips or PCB low-resistance paths under abnormal conditions.
[0083] Example 3: Based on Examples 1 and 2, this example describes the hardware implementation of a flash memory physical destruction system based on negative voltage injection. This system is installed in the SSD board-level circuitry and includes a controller, a destruction enable interface, an onboard low-voltage power supply input, a NAND normal operating power supply, a normal power supply isolation unit, a negative voltage generation module, a multi-channel MOS control circuit, a current sampling unit, a VCC-GND impedance detection unit, a VCC_i residual voltage detection unit, a VCC_i residual release branch, a common negative voltage output node release unit, and a parameter storage unit. The parameter storage unit includes at least one of a parameter storage area, a one-time programmable storage area, or a hardware coding network, used to store residual voltage threshold, effective negative voltage threshold, detection current, initial short-circuit threshold, single injection duration, maximum number of injections per chip, residual release time, negative voltage establishment time, recovery time, hardware overcurrent threshold, and corresponding preset emergency values. The parameter storage unit also includes an abnormal status recording area. The abnormal status recording area is used to record the valid flag of the destruction process, the currently processed NAND number, the current injection count, the current process stage, the processed NAND flag, the abnormal chip flag, the VCC-GND equivalent impedance reference before injection, and the status verification value during the execution of the destruction process. This allows the controller to determine whether to continue the chip-by-chip destruction process or trigger the global locking condition after power failure and power restoration.
[0084] like Figure 3The overall hardware structure diagram shown illustrates that the flash memory physical destruction system based on negative voltage injection in this embodiment is installed in the SSD board-level circuitry. It includes the SSD's native 5V power supply, an onboard low-voltage power supply input terminal, a destruction enable interface, a controller, a NAND normal operating power supply, a normal power supply isolation unit, a negative voltage generation module, a common negative voltage output node, a common negative voltage output node release unit, a multi-channel MOS control circuit, a current sampling unit, a VCC-GND impedance detection unit, a VCC_i residual voltage detection unit, a VCC_i residual release branch, and the NAND array. The destruction enable interface inputs a destruction enable signal to the controller. After confirming the validity of the destruction enable signal, the controller controls the normal power supply isolation unit to shut off the power supply path between the NAND normal operating power supply and each NAND power supply terminal, and controls the negative voltage generation module to generate a negative voltage output from the onboard low-voltage power supply. The output terminal of the negative voltage generation module forms a common negative voltage output node. The multi-channel MOS control circuit sequentially conducts the corresponding destruction MOS branch according to the multiple control enable signals output by the controller, so that the common negative voltage output node is sequentially connected to the VCC terminal of the current NAND. The current sampling unit is used to collect the injected current, the VCC-GND impedance detection unit is used to detect the equivalent impedance before and after injection, the VCC_i residual voltage detection unit is used to detect the residual voltage at each NAND power supply terminal, the VCC_i residual release branch is used to release residual charge, and the common negative voltage output node release unit is used to release the charge of the common negative voltage output node when destruction is complete or abnormal exit occurs. Through this structure, multi-chip negative voltage injection, status detection, abnormal handling, and safe release can be achieved. Specifically, the SSD native 5V power supply is the original low-voltage input power supply for the solid-state drive board-level circuitry; the onboard low-voltage power supply input terminal is a low-voltage power supply branch derived from the SSD native 5V power supply, used to provide input power to the controller and negative voltage generation module; the NAND normal operation power supply is the NAND operating power supply generated by the onboard power conversion circuit from the SSD native 5V power supply, used to supply power to the VCC_i of each NAND during normal SSD read / write operation. After the destruction process is initiated, the controller shuts off the normal power supply isolation switch between the normal power supply of the NAND and the VCC_i of each NAND, so that the normal power supply of the NAND is no longer connected to the VCC_i of each NAND; the onboard low-voltage power supply input terminal still supplies power to the controller and the negative pressure generation module to support negative pressure generation, chip-by-chip selection, detection and abnormal release.
[0085] like Figure 4The diagram shows the hardware branch diagram corresponding to a single NAND chip. The power supply terminal VCC_i of the i-th NAND chip is connected to the normal operating power supply of the NAND through the normal power supply isolation switch K_i, and is connected to the common negative voltage output node through the destruction MOS branch QD_i. In the normal operating state, the normal power supply isolation switch K_i is turned on, and the destruction MOS branch QD_i is turned off. In the destruction state, the controller turns off the normal power supply isolation switch K_i and controls the destruction MOS branch QD_i to turn on through the multiplexer enable signal, so that the common negative voltage output node is connected to the VCC_i of the i-th NAND chip through QD_i and the injection current sampling resistor Rs_i, thereby forming a negative injection voltage between VCC_i and GND. The current sampling unit in the diagram is used to collect the injection current in the destruction MOS branch corresponding to the i-th NAND chip and feed it back to the controller. sense Signal; the impedance detection gating switch KT_i is used to select the impedance detection path of the i-th NAND chip before or after injection. The VCC-GND impedance detection unit feeds back Z to the controller based on the detection result. feedback The VCC_i residual voltage detection unit is used to detect the residual voltage at the power supply terminal of the i-th NAND chip and feed it back to the controller. res The residual release branch of VCC_i is activated after the controller outputs the residual release control signal, releasing the residual charge on VCC_i through the release switch and release resistor. This diagram illustrates the specific hardware connections of a single NAND chip during normal power supply, negative voltage injection, current sampling, impedance detection, and residual release processes.
[0086] The normal power supply isolation unit includes a normal power supply isolation switch corresponding to each NAND flash memory chip. This switch connects the normal operating power supply of the NAND flash memory chip to the corresponding NAND flash memory chip's VCC_i. It can be implemented using a load switch, a back-to-back MOSFET switch, or a power switch with reverse blocking capability. In normal operating condition, the normal power supply isolation switch is on, allowing the normal operating power supply to power the corresponding NAND flash memory chip. In deactivated condition, the controller turns off the normal power supply isolation switch and latches the normal power supply disabled state, preventing the normal operating power supply from connecting to the VCC_i of any NAND flash memory chip.
[0087] The negative voltage generation module connects to the onboard low-voltage power supply input and generates a negative voltage output relative to GND under the power enable signal output by the controller. The negative voltage generation module can be implemented using an inverting charge pump, an inverting DC-DC converter, or an isolated flyback converter. The output of the negative voltage generation module connects to a common negative voltage output node, which is the common negative potential connection node between the negative voltage output of the negative voltage generation module and the input of each destroyed MOS branch. The common negative voltage output node is equipped with a negative voltage feedback sampling channel, which converts the voltage VNEG of the common negative voltage output node into a voltage signal that the controller can acquire, used to determine whether the common negative voltage output node has reached the effective negative voltage threshold.
[0088] The multi-channel MOS control circuit includes multiple destroyable MOS branches corresponding one-to-one with multiple NAND chips. Each destroyable MOS branch is connected between a common negative voltage output node and the VCC_i of the corresponding NAND chip. The destroyable MOS branches can be constructed using back-to-back negative voltage-resistant MOSFETs to block the uncontrolled current path formed by the MOSFET body diode in the off state. The multi-channel MOS control circuit also includes a negative voltage-side gate drive circuit and a default turn-off resistor. The gate of the destroyable MOS branch is controlled by the negative voltage-side gate drive circuit; when the controller is reset, powered down, or the drive signal is abnormal, the default turn-off resistor keeps each destroyable MOS branch off. The controller outputs multiple control enable signals in a preset sequence, ensuring that the multi-channel MOS control circuit only turns on the destroyable MOS branch corresponding to the current NAND chip, while keeping the destroyable MOS branches corresponding to other NAND chips off.
[0089] The VCC_i residual voltage detection unit includes a voltage divider sampling circuit connected to the VCC_i of each NAND flash memory, a detection amplification circuit, and an analog-to-digital conversion channel. It is used to detect the residual voltage of VCC_i to GND of each NAND flash memory after the normal power supply isolation switch is turned off. The VCC_i residual release branch includes a discharge resistor or a controlled discharge switch. When the residual VCC_i voltage of any NAND flash memory exceeds the residual voltage threshold, the controller releases the residual charge of that node through the corresponding VCC_i residual release branch until the residual voltage is no higher than the residual voltage threshold, or until a preset residual release time is reached.
[0090] The VCC-GND impedance detection unit includes a detection current source, a detection current-limiting resistor, a detection gating switch, and a voltage sampling channel. It is used to detect the equivalent impedance between VCC_i and GND of the current NAND flash memory before and after negative voltage injection. The same detection current, detection direction, gating path, and conversion rules are used for both pre-injection and post-injection detection. The controller obtains the VCC-GND equivalent impedance reference before injection and the VCC-GND equivalent impedance after injection, and determines the impedance change based on the difference between the two.
[0091] The current sampling unit is located in the current path of the destroyed MOS branch or the common negative voltage output node, and can be implemented using sampling resistors, differential amplifiers, and analog-to-digital conversion channels. The current sampling unit can be set independently for each destroyed MOS branch, or a common current sampling structure can be used. When using a common current sampling structure, the multi-channel MOS control circuit allows only one destroyed MOS branch to be turned on at any given time, ensuring that the common sampling current uniquely corresponds to the currently selected NAND. The controller calculates the injection current surge based on the injection current timing data output by the current sampling unit, and controls the multi-channel MOS control circuit to turn off the currently destroyed MOS branch when the injection current exceeds the hardware overcurrent threshold.
[0092] The common negative pressure output node release unit is connected between the common negative pressure output node and the safety potential, and can be implemented using a bleed resistor, a controlled bleed switch, or a combination of both. When all NAND processing is completed, the common negative pressure output node fails to meet the standard, negative pressure recovery fails, or a global lockout condition is triggered, the controller shuts down the negative pressure generation module and turns on the common negative pressure output node release unit, causing the common negative pressure output node to release to a safety potential close to GND.
[0093] The controller can be implemented using dedicated safety control logic within the SSD controller, an independent microcontroller, a programmable logic device, or a hardware state machine. The controller connects to the destruction enable interface, normal power supply isolation unit, negative voltage generation module, multi-channel MOS control circuit, current sampling unit, VCC-GND impedance detection unit, VCC_i residual voltage detection unit, VCC_i residual release branch, common negative voltage output node release unit, and parameter storage unit. The controller performs the following functions: destruction enable signal confirmation, normal power supply isolation, residual voltage detection and release, enabling the negative voltage generation module, valid judgment of the common negative voltage output node, multi-channel control enable output, single injection timing, injection current mutation calculation, VCC-GND impedance mutation calculation, electrical parameter failure criterion judgment, single-chip maximum injection count, chip-by-chip anomaly handling, global anomaly shutdown, and common negative voltage output node release.
[0094] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. A flash memory physical destruction method based on negative voltage injection, applied to a solid-state drive comprising multiple flash memory chips, characterized in that, include: Receive and confirm that the destroy enable signal is valid; Shut down or isolate the normal power supply path for each flash memory chip; The output power enable signal enables the negative voltage generation module to generate a negative voltage output with a negative value relative to the ground terminal from the onboard low voltage power supply. The multi-channel control enable signal is output in a preset order. The multi-channel MOS control circuit turns on the corresponding destroy MOS branch of the current flash memory chip, so that the negative voltage output is connected to the power supply terminal of the current flash memory chip, and a negative injection voltage is formed between its power supply terminal and ground terminal. Keep the current destroyed MOS branch on for a preset single injection duration, causing the current flash memory chip to physically fail. Shut down the current MOS branch to destroy and switch to the next flash memory chip until all target flash memory chips have been processed and then shut down the negative voltage generation module.
2. The flash memory physical destruction method based on negative voltage injection according to claim 1, characterized in that, The receipt and confirmation of the validity of the destruction enable signal includes: Detect the destroy enable signal output by the destroy enable interface; When the destruction enable signal remains in the triggered state for a duration that reaches the preset trigger confirmation time, the destruction enable signal is deemed valid. When the destruction enable signal returns to the non-triggered state within the preset trigger confirmation time, the destruction process will not be started, and the normal power supply status of each flash memory chip will be maintained. The preset trigger confirmation time is determined based on the destruction enable signal sampling period and the number of trigger anti-shake sampling times.
3. The flash memory physical destruction method based on negative voltage injection according to claim 2, characterized in that, The shutdown or isolation of the normal power supply path of each flash memory chip includes: Turn off the power supply isolation switch between each flash memory chip's power supply terminal and the normal operating power supply, and maintain the normal power supply disabled state; Before the normal power supply restriction is lifted, the solid-state drive host interface, flash memory read / write channel and other logic cannot reconnect the power supply path between the normal power supply and the power terminals of each flash memory chip. After the normal power supply isolation switch is turned off, the residual voltage of each flash memory chip's power supply terminal relative to the ground terminal is detected. When the residual voltage is higher than the residual voltage threshold, the residual charge at the power supply terminal of the corresponding flash memory chip is released.
4. The flash memory physical destruction method based on negative voltage injection according to claim 3, characterized in that, The output power enable signal enables the negative voltage generation module to generate a negative voltage output with a negative value relative to the ground terminal from the onboard low-voltage power supply, including: After the normal power supply path of each flash memory chip is turned off or isolated, the controller outputs a power enable signal to the negative voltage generation module. The negative pressure generation module receives onboard low-voltage power and generates a negative voltage output with a negative value relative to the ground terminal through an inverse phase conversion method. The negative voltage output is led to a common negative voltage output node, which is a common negative potential connection node between the negative voltage output terminal of the negative voltage generation module and the input terminal of each destroyed MOS branch. When the voltage of the common negative voltage output node reaches the effective negative voltage threshold, the common negative voltage output node is determined to be in an injectable state.
5. The flash memory physical destruction method based on negative voltage injection according to claim 4, characterized in that, The process of outputting multiple control enable signals in a preset sequence, and the multi-channel MOS control circuit turning on the corresponding destroy MOS branch of the current flash memory chip, allows the negative voltage output to be connected to the power supply terminal of the current flash memory chip, forming a negative injection voltage between its power supply terminal and ground terminal, including: The controller sets the currently processed object as the i-th flash memory chip according to a preset order; The controller outputs a multi-channel control enable signal corresponding to the i-th flash memory chip to the multi-channel MOS control circuit. The multi-channel MOS control circuit turns on the destroy MOS branch corresponding to the i-th flash memory chip and keeps the destroy MOS branches corresponding to other flash memory chips off. The common negative voltage output node is connected to the power supply terminal of the i-th flash memory chip via the destruction MOS branch corresponding to the i-th flash memory chip, so that the potential of the power supply terminal of the i-th flash memory chip is lower than the potential of the ground terminal, thus forming a negative injection voltage.
6. The flash memory physical destruction method based on negative voltage injection according to claim 5, characterized in that, The step of keeping the currently destroyed MOS branch on for a preset single injection duration, causing the current flash memory chip to physically fail, includes: The controller reads or calls the preset single injection duration and starts the hardware timer; During the hardware timer's timing, the multi-channel MOS control circuit keeps the destroy MOS branch corresponding to the current flash memory chip on, so that the negative injection voltage is applied to the power rail, protection structure or parasitic conduction path inside the current flash memory chip. When the hardware timer expires, regardless of whether the software process is complete, the multi-channel MOS control circuit shuts down the currently destroyed MOS branch. The preset single injection duration is used to limit the time during which a single flash memory chip is continuously connected to the common negative pressure output node.
7. The flash memory physical destruction method based on negative voltage injection according to claim 6, characterized in that, The process of shutting down the currently destroyed MOS branch and switching to the next flash memory chip, until all target flash memory chips have been processed and the negative voltage generation module is shut down, includes: After the current flash memory chip completes one negative voltage injection, the controller shuts down the corresponding destruction MOS branch of the current flash memory chip; The controller determines the processing result of the flash memory chip based on the current injection current change and the impedance change before and after injection. When the current flash memory chip's processing result is that the negative pressure physical destruction process has been completed, or when the current flash memory chip's processing result is that the abnormal chip has been processed, the controller will mark the current flash memory chip as processed; The controller determines whether there are still unprocessed target flash memory chips; When there is an unprocessed target flash memory chip, the controller sets the next flash memory chip as the current flash memory chip according to a preset order and outputs the corresponding multiplex control enable signal. When there are no unprocessed target flash memory chips, the controller shuts down the negative pressure generation module and releases the common negative pressure output node to a safe potential.
8. The flash memory physical destruction method based on negative voltage injection according to claim 7, characterized in that, The process of determining the current flash memory chip's processing result based on the current injection current change and impedance change before and after injection includes: After the current flash memory chip completes one negative voltage injection, the injection current timing data of the corresponding destroyed MOS branch of the current flash memory chip is collected, and the injection current mutation amount is determined according to the average current difference between adjacent sampling windows. After shutting down the current destroyed MOS branch, the equivalent impedance after injection between the power supply terminal and the ground terminal of the current flash chip is detected, and the impedance change amount is determined based on the difference between the equivalent impedance after injection and the equivalent impedance reference before injection. When the injection current mutation reaches the current mutation threshold and the impedance mutation reaches the impedance mutation threshold, the current flash memory chip is determined to have reached the electrical parameter failure criterion. The electrical parameter failure criterion is used as the confirmation condition that the current flash memory chip has completed the negative pressure physical destruction process, and the processing result of the current flash memory chip is determined to have completed the negative pressure physical destruction process. When either the injection current surge or the impedance surge fails to reach the corresponding threshold, and the current injection count of the current flash memory chip fails to reach the maximum injection count for a single chip, the controller applies additional negative pressure injection to the current flash memory chip. If either the injection current mutation or the impedance mutation does not reach the corresponding threshold, and the number of injections performed by the current flash memory chip has reached the maximum number of injections per chip, the processing result of the current flash memory chip will be determined as a processed abnormal chip.
9. The flash memory physical destruction method based on negative voltage injection according to claim 1, characterized in that, It also includes exception branch handling: When the destruction enable signal is not continuously maintained until the preset trigger confirmation time, the controller will not enter the destruction process, the normal power supply isolating switch will remain in its original normal working state, the negative voltage generation module will not start, and all destruction MOS branches will remain off. When the destruction enable signal is determined to be valid, the controller writes the destruction process status into the abnormal status record area. The abnormal status record area records at least the destruction process validity flag, the current processing object, the current injection count, the interrupt recovery count, the processed flash memory chip mark, the abnormal chip mark, the current process stage, the equivalent impedance reference before injection, the current current mutation amount corresponding to the current injection, the injection current data validity flag, and the status verification value. When the residual voltage at the power supply terminal of any flash chip is still higher than the residual voltage threshold within the preset residual release time, or when the common negative voltage output node fails to reach the effective negative voltage threshold within the preset negative voltage establishment time, the controller will prevent any destroyed MOS branch from conducting, shut down or keep the negative voltage generation module shut down, and output the corresponding abnormal handling result. When the actual negative voltage amplitude of the common negative voltage output node exceeds the current effective negative voltage amplitude range during the injection process, the controller shuts down the destruction MOS branch corresponding to the current flash memory chip. If the common negative voltage output node does not re-enter the current effective negative voltage amplitude range within the preset recovery time, or if the negative voltage amplitude is too large, the negative voltage generation module is shut down, all destruction MOS branches are shut down, and the negative voltage injection process of subsequent flash memory chips is stopped. When the equivalent impedance before injection of the current flash memory chip cannot be obtained, the equivalent impedance before injection does not meet the effective reference condition, the injection current exceeds the hardware overcurrent threshold, or the sampling channel is saturated and cannot obtain the effective current change amount, the controller records the abnormal processing result of the current flash memory chip. When a power outage occurs and power is restored during the destruction process, the controller reads the abnormal status record area and verifies the status verification value. If the status verification value is invalid, the current processing object cannot be confirmed, or the normal power supply prohibition status has taken effect but cannot be confirmed at the current process stage, then the global locking condition is triggered. If the abnormal status recording area is valid and there are still unprocessed flash memory chips or flash memory chips whose processing results have not been confirmed, the controller determines that a destruction interruption restart event has occurred, increments the interrupt recovery count by one, and resumes chip-by-chip processing based on the current processing object, current injection count, processed flash memory chip mark, current process stage, equivalent impedance reference before injection, current injection current mutation amount, and injection current data validity flag recorded in the abnormal status recording area. If negative voltage injection was in progress before the power failure, the controller will record this interrupted injection as invalid injection. After the residual voltage safety condition and the common negative voltage output node validity condition are met again, the negative voltage injection will be re-executed on the current flash memory chip. If the post-injection impedance detection was in progress or the single-chip processing result was not written before the power failure, the post-injection equivalent impedance detection will be re-executed, and the processing result will be determined by combining the saved pre-injection equivalent impedance reference, current mutation amount and injection current data validity flag. When the exception handling result is a single-chip exception and the global locking condition is not triggered, the controller marks the current flash memory chip as a processed exception chip and switches to the next flash memory chip. When the abnormal status record area verification fails, the current processing object cannot be confirmed, the number of interrupt recovery attempts reaches the preset interrupt recovery attempt limit, the common negative voltage output node cannot be released to a safe potential, the residual voltage at the power supply terminal of any flash chip cannot be released below the residual voltage threshold, or the common negative voltage output node cannot be restored to the current effective negative voltage amplitude range, the global locking condition is determined to be triggered. When the global lockout condition is triggered, the controller shuts down the negative voltage generation module, shuts down all destruction MOS branches, releases the charge of the common negative voltage output node, and maintains the power-off isolation state of all flash memory chips.
10. A flash memory physical destruction system based on negative voltage injection, applied to a solid-state drive comprising multiple flash memory chips, characterized in that, include: The system includes a controller, a destruction enable interface, an onboard low-voltage power supply input, a normal operating power supply, a normal power supply isolation unit, a negative voltage generation module, a multi-channel MOS control circuit, a current sampling unit, a VCC-GND impedance detection unit, a residual voltage detection unit, a residual release branch, a common negative voltage output node release unit, and a parameter storage unit. The destruction enable interface is connected to the controller and is used to output a destruction enable signal to the controller; The normal power supply isolation unit is connected between the normal power supply and the power supply terminal of each flash memory chip, and is used to shut down or isolate the normal power supply path of each flash memory chip under the control of the controller. The negative pressure generation module is connected to the onboard low-voltage power supply input terminal, and generates a negative pressure output with a negative value relative to the ground terminal under the action of the power enable signal output by the controller. The output terminal of the negative pressure generation module forms a common negative pressure output node. The multi-channel MOS control circuit includes multiple destruction MOS branches corresponding to multiple flash memory chips. Each destruction MOS branch is connected between the common negative voltage output node and the power supply terminal of the corresponding flash memory chip. It is used to turn on the destruction MOS branch corresponding to the current flash memory chip under the action of the multi-channel control enable signal output by the controller, and keep other destruction MOS branches off. The current sampling unit is used to collect the injection current of the MOS branch corresponding to the current flash memory chip being destroyed; The VCC-GND impedance detection unit is used to detect the equivalent impedance before and after injection between the power supply terminal and the ground terminal of the current flash memory chip. The residual voltage detection unit is used to detect the residual voltage between the power supply terminal and the ground terminal of each flash memory chip. The residual release branch is connected to the power supply terminal of each flash memory chip and is used to release the residual charge of the power supply terminal when the residual voltage of the power supply terminal of the corresponding flash memory chip is higher than the residual voltage threshold. The common negative pressure output node release unit is used to release the charge of the common negative pressure output node when all target flash memory chips have been processed, negative pressure recovery fails, overvoltage shutdown occurs, abnormal exit occurs, or global lockout conditions are triggered. The parameter storage unit is used to store threshold parameters, duration parameters, current parameters, impedance parameters and corresponding preset emergency values, and includes an abnormal state recording area. The abnormal state recording area is used to record the effective flag of the destruction process, the current processing object, the current injection count, the number of interruption recovery counts, the processed flash memory chip mark, the abnormal chip mark, the current process stage, the equivalent impedance reference before injection, the current mutation amount corresponding to the current injection, the effective flag of the injection current data and the status verification value. The controller is used to execute the flash memory physical destruction method based on negative voltage injection as described in any one of claims 1 to 9.