On-line memory monitoring system and methods
11 claims: 3 independent, 8 dependent
- 1A method of improving memory reliability in a computer comprising:(a) providing an error correction code with data stored in memory;(b) detecting and correcting single-bit memory errors as they occur using the error correction code;(c) determining the rate at which single-bit errors occur;and (d) providing a warning if the operating conditions are abnormal whereby to indicate the potential occurrence of multiple-bit errors. characterised by (e) employing a statistical inference method to determine from said rate, and average failure rates for the memory, whether the memory is running under normal or abnormal conditions;
- 2On-line memory monitoring apparatus comprising:a processor;a read/write random access memory coupled to the processor, the random access memory being configured to store data words and associated error correction codes;error detection and correction circuitry coupled to the read/write random access memory, the error detection and correction circuitry being configured to determine the specific error correction code to be written to the memory with each data word to be written to memory, and to detect and correct single-bit errors in data and associated error correction codes as read from memory;and an error monitor configured to respond to the error detection and correction circuitry to provide a warning indicating the potential occurrence of multiple-bit errors, if the memory is running under abnormal conditions, characterised in that the monitor generates a log of detected single-bit errors and in that the provision of said warning is computed by statistical inference from the rate at which single-bit memory errors have occurred and average failure rates from the memory.
- 3The apparatus of Claim 2, wherein the processor is configured to write the corrected data and associated error correction code back into the memory at the memory location from which it was read upon detection and correction of an error in data and associated error correction code read from the memory.
- 4The apparatus of Claim 3, wherein the error monitor is configured to respond to the error detection and correction circuitry to provide a said warning if the rate at which single-bit memory errors have occurred over either a first or a second time period exceeds first and second predetermined memory error rate limits, respectively.
- 5The apparatus of Claim 4 wherein the error monitor is configured to provide a said warning indicative of a memory failure if the rate at which single-bit memory errors have occurred over the first time period exceeds the first predetermined memory error rate limit, and of providing a said warning indicative of an unusually high error rate if the rate at which single-bit memory errors have occurred over the second time period exceeds the second predetermined error rate limit.
- 6A system for on-line memory monitoring responsive to the detection and correction of a single-bit memory error, the system including code configured for storage on a computer-readable apparatus and executable by a computer, the code including a plurality of modules, the system including:a first module configured to maintain a single-bit memory error log;a second module configured to respond to the detection and correction of a single-bit memory error to determine using the memory error log if the rate at which single-bit memory errors have occurred exceeds a predetermined limit;a third module logically coupled to the second module and configured to provide a warning if the second module determines that the rate at which single-bit memory errors have occurred exceeds the predetermined limit;and a fourth module logically coupled to the first module and configured to update the error log upon the detection and correction of a single-bit memory error;wherein the system employs a statistical inference method to determine from said rate, and average failure rates for the memory, whether the memory is running under normal or abnormal operating conditions, abnormal operating conditions corresponding to the single-bit memory rate exceeding the predetermined limit;and wherein the warning is indicative of abnormal operating conditions and the potential occurrence of multiple-bit errors.
- 7The system of Claim 6, further comprising a fifth module configured to overwrite the memory after detection and correction of a memory error.
- 8A system of Claim 6, wherein the second module is configured to respond to the detection and correction of a single-bit memory error to determine using the memory error log if the rate at which single-bit memory errors have occurred exceeds a first or a second predetermined limit and the third module is configured to provide a warning of a first character if the second module determines that the rate at which memory errors have occurred exceeds the first predetermined limit, and further comprising a fifth module configured to provide a warning of a second character if the second module determines that the rate at which memory errors have occurred exceeds the second predetermined limit.
- 9A method as claimed in Claim 1, including the steps of determining the rate at which single-bit memory errors have occurred over a first elapsed time and determining the rate at which single-bit memory errors have occurred over a second elapsed time longer than the first elapsed time, and wherein a said warning is also provided when the rate at which single-bit memory errors have occurred over either the first or the second time period exceeds first and second predetermined memory error rate limits, respectively.
- 10A method as claimed in Claim 1, further comprising:using the corrected data as error-free data;writing the corrected data and error correction code back into the same memory location from which it was read;and providing a respective warning if the rate at which single-bit memory errors have occurred exceeds a predetermined limit.
- 11The apparatus as claimed in Claim 2, further comprising:a CPU/memory board having at least one bus connector for connecting to a system bus, wherein the processor is coupled to the bus connector, the processor being configured to write the corrected data and associated error correction code back into the memory at the memory location from which it was read upon detection and correction of an error in data and associated error correction code read from the memory.
Independent claims11
40 paragraphs in 3 sections, as filed
1.
Field of the Invention
0001The present invention relates to the field of computer memory systems and the performance thereof.
2.
Prior Art
0002Most computer systems include, among other things, substantial storage capacity in the form of random access memory, currently most commonly in the form of dynamic random access memory (DRAM). Such memories and systems incorporating such memories are known to be subject to certain types of errors. For instance, in the memory itself, the errors may be generally classified as either soft errors or hard errors. Soft errors are errors which occasionally occur, but are not repeatable, at least on a regular basis. Thus, soft errors alter data, though the stored data may be corrected by rewriting the correct data to the same memory location. A major cause of soft errors in DRAMs are alpha particles which, because of the very small size of DRAM storage cells, can dislocate sufficient numbers of electrons forming the charge determining the state of the cell to result in the cell being read as being in the opposite state. This results in a relatively randomly occurring, single-bit memory error which, because of its very low likelihood of reoccurrence in the near future, can be corrected by rewriting the correct data to that memory location. Soft errors can also be related to noise in the memory system, or due to unstable DRAMS or SIMMs (DRAMs in the form of single inline memory modules).
0003Hard errors in the memory are repeatable errors which alter data due to some fault in the memory, and cannot be recovered by rewriting the correct data to the same memory location. Hard errors can occur when one memory cell becomes stuck in either state, or when SIMMs are not properly seated.
0004Silent failures are failures that cannot be detected by the system. For example, if a standby part fails inside a system having redundant parts, most systems will remain unaware of the failure. However, although the system is still functional, it has lost its redundancy as if the same had never been provided, and is now vulnerable to a single failure of the operating part. Soft errors and hard errors can be either be single-bit or multiple-bit memory errors, and can also be silent failures under certain conditions.
0005Relevant background art is described in the following two documents.
0006IBM Technical Disclosure Bulletin, November 1969, Vol. 12, No. 6, page 895 describes an error frequency warning detector on storage with an ECC, wherein in a data store using error correction to correct single-bit errors and detect double-bit errors, an error frequency counter is used to indicate the rate at which single-errors are occurring. The error rate indicates the amount by which the performance of the store is degraded by correcting single-bit errors. The error frequency counter is incremented each time a single-bit error occurs. An interval timer resets the counter after a predetermined time interval. The count is compared with a preset limit. An error frequency limit interrupt signal is generated when the count is equal to or greater than the error frequency limit. The interrupt signal causes a warning message to be printed.
0007US-A-5,263,032 describes the operation of a computer system with a corrected read data function in which a computer system having a memory with an ECC function employs an improved method for handling corrected read data events, so transient errors caused by alpha particle hits in DRAMs may be distinguished from hard errors. When a corrected read data event occurs, a footprint defining its location is compared with previously-stored footprints to determine if this location has failed before. Also, a location showing a corrected read data event is "scrubbed" (data is read, corrected and rewritten) so transient error locations are removed. If another corrected read data event occurs for this same location, after scrubbing, then the location is assumed to have a hard fault, and so the page containing this location is replaced.
0008Currently, server systems manufactured and sold by Sun Microsystems, Inc., assignee of the present invention, are implemented with an error correction code (ECC) to protect the system from single-bit memory errors. In the event of a single-bit memory error in the data or the correction code as read from memory, the system automatically corrects the error before the data retrieved from memory is used. This is implemented using an 8-bit KANEDA error correction code for the 64-bit dataword of the memories, making the entire codeword 72-bits wide. The actual error detection and correction operation is done, for instance, by dedicated ECC circuitry as part of the processor module so that on the occurrence of a single-bit memory error in the 72-bit codeword received from memory, the same will automatically be corrected before being presented to the processor. Also, upon the occurrence of a single-bit error and the correction thereof by the ECC circuitry, the processor is alerted to that fact so that the processor will include the additional step of writing the corrected codeword (data and ECC) back to memory on the unverified assumption that the single-bit error was a soft error. In such systems, the I/O of the system consists of a 64-bit word, the applicable ECC code being tacked onto any dataword before the resulting 72-bit codeword is written to memory.
0009Also, in the current systems of the type described, an automatic reset is initiated upon the occurrence of a double-bit memory error. This, of course, results in an interruption of service by the system, loss of any ongoing communication, and loss of data. Because a double-bit error is a rare event under normal operating conditions, such system failures caused by double-bit memory errors are also rare. However, normal operating conditions may be defined as operation without excessive memory errors occurring in the system, wherein the ECC implementation described provides adequate protection for the integrity of the system memory. But two events can change a normal operating condition into an abnormal operating condition, specifically that (1) the memory subsystem has excessive single-bit soft errors, and (2) the memory subsystem has single-bit hard errors. These occurrences obviously greatly increase the probability that a normally expected soft error will become a second bit error causing automatic interruption of the system.
0010In the current ECC implementation, no memory error log is visible to the system administrator. Thus, whenever there is a single-bit memory error, the system simply corrects it and continues to run. Under normal operating conditions, protecting the system from single-bit errors is the purpose of the ECC. Under abnormal operating conditions, the ECC actually masks the underlying problem. When the memory subsystem has either excessive single-bit soft errors or single-bit hard errors, they become silent failures in the current ECC implementation. The system then becomes prone to single-bit errors so that an additional single-bit memory error combined with the silent failure may result in a double-bit error, bringing the system down.
SUMMARY OF THE INVENTION
0011The present invention as defined by the claims specifies an on-line memory monitoring system, an apparatus and a method wherein memory subsystem performance is tracked to detect substandard performance and alert a system administrator of the nature of the substandard performance so corrective action can be taken before a system crash and/or automatic reset occurs. A computer system incorporating the invention includes a memory and a processor, wherein the memory storage includes data storage and error correction code storage for each dataword. The system further includes automatic error detection and correction circuitry and software which monitors the occurrence of correction of errors and compares their frequency with the known frequency of soft errors for the memory devices being used to determine whether an alert is to be given and the nature of any such alert.
0012The on-line memory monitoring system uses a unique statistical inference method based on the number of single-bit memory errors and the frequency of their occurrence as observed by the system to provide the appropriate alert.
BRIEF DESCRIPTION OF THE FIGURES
0013Figure 1 is a block diagram of the internal structure of the CPU/memory board of a system which may incorporate the present invention.
0014Figure 2 is a logic flow diagram for the operation of 'the on-line memory monitoring system.
0015Figure 3 illustrates a typical system that may use the present invention.
DETAILED DESCRIPTION OF THE INVENTION
0016First referring to Figure 1, a block diagram of the internal structure of the CPU/memory board for the Enterprise X000 server systems to be introduced by Sun Microsystems, Inc., assignee of the present invention. As may be seen therein, the CPU/memory board contains two UltraSPARC modules containing high performance superscalar 64-bit SPARC processors. These modules are coupled through address and data controllers to memory and to a centerplane connector for connecting to a system bus structure. Also shown in Figure 1 is a boot controller and other on-board devices, their specific structure being well known and not important to the present invention.
0017As with the prior art systems of Sun Microsystems, Inc., the memory is 72 bits wide, providing 64 bits of data and 8 bits of ECC. However in accordance with the present invention, continuous on-line monitoring of memory errors is provided. As soon as the memory is found to have excessive single-bit soft errors relative to known statistics for such memories, or single-bit hard errors, a warning or alert may be presented to the system administrator so that corrective action can be taken. In the preferred embodiment, the on-line monitoring is done under software control, and continually monitors the system, logging all single-bit errors and the memory device in which such errors occurred. Upon the occurrence of another error, the on-line monitoring software analyzes the error log using statistical analysis to identify any abnormal operating condition that may be indicated. Since occasional memory errors are to be expected for dynamic random access memories (DRAMs), single-bit errors encountered in a properly operating system will be found to not indicate an abnormal operating condition, but once the rate of errors indicate an abnormal operating condition, the system administrator can be alerted to the condition and the memory device causing the problem.
0018An abnormal operating condition will be caused by either type of memory error, specifically excessive single-bit soft errors, or single-bit hard errors. From a system point of view, both types of errors are single-bit errors that occur at an excessive rate. The only difference between the two is that the hard errors can show up each time that part of the memory is accessed, while the soft errors may appear less frequently. This occurs because the hard errors are not correctable in memory by merely writing the corrected information back into memory. In that regard, note that a bad memory cell hung in one state may or may not show up on any read access thereto as a hard error. As an example, if an instruction, or fixed data, is stored at that location in memory, one will either get a single-bit error every time that location is accessed for reading if the cell is hung in the opposite state from the corresponding bit in the instruction or fixed data, or no error will be encountered when that location is accessed for reading if the cell is hung in the same state as the corresponding bit in the instruction or fixed data. On the other hand, if the location is used for storage of random or near random data, then the fault will result in a single-bit error about half the time new data therein is read.
0019Memory is made of DRAMS, for which the frequency and distribution of single-bit errors under normal operating conditions are known. If the detected DRAM single-bit errors far exceed what is expected under normal operating conditions, it can be concluded that the memory is having excessive single-bit errors. During normal operating conditions, only soft errors should occur in the DRAM, and then only within the reasonably expected frequency for such DRAMs. Single-bit soft errors occur in DRAMs in a Poisson distribution as follows:<maths id="math0001" num=""><math display="block"><mrow><mtext>P(x) = </mtext><mfrac><mrow><msup><mrow><mtext>(λt)</mtext></mrow><mrow><mtext>x</mtext></mrow></msup></mrow><mrow><mtext>x !</mtext></mrow></mfrac><msup><mrow><mtext> e</mtext></mrow><mrow><mtext>-λt</mtext></mrow></msup><mtext> x = 0,1,2,...</mtext></mrow></math><img file="EP0806726B1_D0001.tif" /></maths> where: <dl id="dl0001" compact="compact"><dt>t =</dt><dd>time</dd><dt>x =</dt><dd>the number of soft errors during a given time t</dd><dt>λ =</dt><dd>the mean number of soft errors during a given time t representative of the DRAMs used</dd><dt>P(x) =</dt><dd>the probability of encountering x soft errors in a given time t</dd></dl>
0020A Poisson distribution is a single parameter and discrete event distribution.
0021Based on previous testing, exemplary failure rates for certain DRAMs are set out in Table 1: <tables id="tabl0001" num="0001"><table frame="all"><title>Table 1:</title><tgroup cols="3" colsep="1" rowsep="1"><colspec colnum="1" colname="col1" colwidth="52.50mm" /><colspec colnum="2" colname="col2" colwidth="52.50mm" /><colspec colnum="3" colname="col3" colwidth="52.50mm" /><thead valign="top"><row><entry namest="col1" nameend="col3" align="center">Exemplary DRAM Failure Rates</entry></row><row><entry namest="col1" nameend="col1" align="left">Memory Size</entry><entry namest="col2" nameend="col2" align="left">Memory Organization</entry><entry namest="col3" nameend="col3" align="left">Average Failure Rate</entry></row></thead><tbody valign="top"><row><entry namest="col1" nameend="col1" align="left">1 Mb</entry><entry namest="col2" nameend="col2" align="left">1Mx1</entry><entry namest="col3" nameend="col3" align="char" char=",">2,000 FIT*</entry></row><row><entry namest="col1" nameend="col1" align="left">4 Mb</entry><entry namest="col2" nameend="col2" align="left">1Mx4, 4Mx1</entry><entry namest="col3" nameend="col3" align="char" char=",">3,000 FIT</entry></row><row rowsep="1"><entry namest="col1" nameend="col1" align="left">16 Mb</entry><entry namest="col2" nameend="col2" align="left">4Mx4</entry><entry namest="col3" nameend="col3" align="char" char=",">9,000 FIT</entry></row></tbody></tgroup><tgroup cols="3" colsep="0" rowsep="0"><colspec colnum="1" colname="col1" colwidth="52.50mm" /><colspec colnum="2" colname="col2" colwidth="52.50mm" /><colspec colnum="3" colname="col3" colwidth="52.50mm" /><tbody valign="top"><row><entry namest="col1" nameend="col3" align="justify">* One FIT is one failure per 10<sup>9</sup> hours of operation</entry></row></tbody></tgroup></table></tables>
0022Based on the foregoing formula and failure rates in Table 1, a system's failure rate under normal operating conditions can be determined. The Table 2 shows the probability of having 0, 1, 2 and 3 or more failures per SIMM using 1 Mb DRAM. <tables id="tabl0002" num="0002"><table frame="all"><title>Table 2:</title><tgroup cols="5" colsep="1" rowsep="1"><colspec colnum="1" colname="col1" colwidth="31.50mm" /><colspec colnum="2" colname="col2" colwidth="31.50mm" /><colspec colnum="3" colname="col3" colwidth="31.50mm" /><colspec colnum="4" colname="col4" colwidth="31.50mm" /><colspec colnum="5" colname="col5" colwidth="31.50mm" /><thead valign="top"><row><entry namest="col1" nameend="col5" align="center">Probability Table of Single-Bit Soft Errors</entry></row><row><entry namest="col1" nameend="col1" /><entry namest="col2" nameend="col5" align="center">Probability of having x number of soft errors over time per SIMM</entry></row><row><entry namest="col1" nameend="col1" align="center">Time (days)</entry><entry namest="col2" nameend="col2" align="center">x = 0</entry><entry namest="col3" nameend="col3" align="center">x = 1</entry><entry namest="col4" nameend="col4" align="center">x = 2</entry><entry namest="col5" nameend="col5" align="center">x ≥ 3</entry></row></thead><tbody valign="top"><row><entry namest="col1" nameend="col1" align="center">1</entry><entry namest="col2" nameend="col2" align="char" char=".">0.999136</entry><entry namest="col3" nameend="col3" align="char" char=".">0.000863</entry><entry namest="col4" nameend="col4" align="center">3.70E-07</entry><entry namest="col5" nameend="col5" align="char" char=".">1.07E-10</entry></row><row><entry namest="col1" nameend="col1" align="center">2</entry><entry namest="col2" nameend="col2" align="char" char=".">0.998273</entry><entry namest="col3" nameend="col3" align="char" char=".">0.001725</entry><entry namest="col4" nameend="col4" align="center">1.50E-06</entry><entry namest="col5" nameend="col5" align="char" char=".">8.59E-10</entry></row><row><entry namest="col1" nameend="col1" align="center">3</entry><entry namest="col2" nameend="col2" align="char" char=".">0.997411</entry><entry namest="col3" nameend="col3" align="char" char=".">0.002585</entry><entry namest="col4" nameend="col4" align="center">3.40E-06</entry><entry namest="col5" nameend="col5" align="char" char=".">2.90E-09</entry></row><row><entry namest="col1" nameend="col1" align="center">4</entry><entry namest="col2" nameend="col2" align="char" char=".">0.996550</entry><entry namest="col3" nameend="col3" align="char" char=".">0.003444</entry><entry namest="col4" nameend="col4" align="center">6.00E-06</entry><entry namest="col5" nameend="col5" align="char" char=".">6.86E-09</entry></row><row><entry namest="col1" nameend="col1" align="center">5</entry><entry namest="col2" nameend="col2" align="char" char=".">0.995689</entry><entry namest="col3" nameend="col3" align="char" char=".">0.004301</entry><entry namest="col4" nameend="col4" align="center">9.30E-06</entry><entry namest="col5" nameend="col5" align="char" char=".">1.34E-08</entry></row><row><entry namest="col1" nameend="col1" align="center">6</entry><entry namest="col2" nameend="col2" align="char" char=".">0.994829</entry><entry namest="col3" nameend="col3" align="char" char=".">0.005157</entry><entry namest="col4" nameend="col4" align="center">0.000013</entry><entry namest="col5" nameend="col5" align="char" char=".">2.31E-08</entry></row><row><entry namest="col1" nameend="col1" align="center">7</entry><entry namest="col2" nameend="col2" align="char" char=".">0.993970</entry><entry namest="col3" nameend="col3" align="char" char=".">0.006012</entry><entry namest="col4" nameend="col4" align="center">0.000018</entry><entry namest="col5" nameend="col5" align="char" char=".">3.67E-08</entry></row><row><entry namest="col1" nameend="col1" align="center">8</entry><entry namest="col2" nameend="col2" align="char" char=".">0.993112</entry><entry namest="col3" nameend="col3" align="char" char=".">0.006864</entry><entry namest="col4" nameend="col4" align="center">0.000024</entry><entry namest="col5" nameend="col5" align="char" char=".">5.48E-08</entry></row><row><entry namest="col1" nameend="col1" align="center">9</entry><entry namest="col2" nameend="col2" align="char" char=".">0.992254</entry><entry namest="col3" nameend="col3" align="char" char=".">0.007716</entry><entry namest="col4" nameend="col4" align="center">0.000030</entry><entry namest="col5" nameend="col5" align="char" char=".">7.79E-08</entry></row><row rowsep="1"><entry namest="col1" nameend="col1" align="center">10</entry><entry namest="col2" nameend="col2" align="char" char=".">0.991397</entry><entry namest="col3" nameend="col3" align="char" char=".">0.008566</entry><entry namest="col4" nameend="col4" align="center">0.000037</entry><entry namest="col5" nameend="col5" align="char" char=".">1.07E-07</entry></row></tbody></tgroup></table></tables> Once the DRAM's failure rate and failure distribution are determined, the on-line monitoring software can assess the system's operating condition based on the number of memory errors being detected. This can be accomplished by using a statistical analysis.
0023In accordance with the present invention, a statistical inference method is developed to determine whether the system is running under normal operating conditions. This statistical inference method establishes two hypotheses as follows: <ul id="ul0001" list-style="none"><li>1. H<sub>0</sub> means that the DRAM error rate is as listed in Table 1, indicating that the system is running under normal operating conditions.</li><li>2. H<sub>1</sub> means that the DRAM error rate is much higher than what is listed in Table 1, indicating that the system is running under abnormal operating conditions.</li></ul>
0024In this hypothesis test, the criteria for accepting H<sub>0</sub> or H<sub>1</sub> is based on the probability of the number of memory errors per SIMM that are observed during the test period. In the exemplary embodiment, if the probability is less than 0.0001 (0.01% chance of happening), an extremely unlikely event, the H<sub>0</sub> hypothesis is rejected and the alternative H<sub>1</sub> hypothesis is accepted. Rejecting H<sub>0</sub> means that the system, with very little doubt, is having excessive memory errors, and the system administrator should be alerted to take the necessary corrective steps. If the probability is higher than 0.0001, the event is considered to be a sufficiently likely event as to be within the statistics of normal operating conditions and the test continues. Obviously, the threshold between a sufficiently likely event to ignore and a sufficiently unlikely event to provide an alert may be altered as desired.
0025As stated before, the on-line monitoring is done by the processor under software control. Upon the detection of a single-bit error detected and corrected by the ECC circuitry, the processor will carry out the further steps of updating the error log, apply the hypothesis test to the error log information, notify the system administrator of the type and location of the problem if appropriate, and write the corrected data and ECC information back into the memory location from which the data and ECC in error was obtained. The corrected data and ECC is written back into memory on the unverified assumption that the error was a soft error correctable by writing good data (and associated ECC) over the bad data and ECC.
0026To simplify the implementation of the hypothesis test in the on-line monitoring software, the following exemplary set of steps may be used (no particular order of the steps is to be implied herein and in the claims unless and only to the extent a particular step requires the completion of another step before the particular step may itself be completed). The on-line software in this exemplary embodiment will log the memory errors for up to three test periods (time periods) as listed in Table 3. Each time a memory error occurs, the software checks to see if the number of memory errors observed during the three test periods has exceeded the number of memory errors allowed for each of those time periods. <tables id="tabl0003" num="0003"><table frame="all"><title>Table 3:</title><tgroup cols="7" colsep="1" rowsep="1"><colspec colnum="1" colname="col1" colwidth="22.50mm" /><colspec colnum="2" colname="col2" colwidth="22.50mm" /><colspec colnum="3" colname="col3" colwidth="22.50mm" /><colspec colnum="4" colname="col4" colwidth="22.50mm" /><colspec colnum="5" colname="col5" colwidth="22.50mm" /><colspec colnum="6" colname="col6" colwidth="22.50mm" /><colspec colnum="7" colname="col7" colwidth="22.50mm" /><thead valign="top"><row><entry namest="col1" nameend="col7" align="center">Decision Set of Rules</entry></row><row><entry namest="col1" nameend="col1" align="center">DRAM Size</entry><entry namest="col2" nameend="col2" align="center">Test Period 1</entry><entry namest="col3" nameend="col3" align="center"># of Errors Allowed per SIMM</entry><entry namest="col4" nameend="col4" align="center">Test Period 2</entry><entry namest="col5" nameend="col5" align="center"># of Errors Allowed per SIMM</entry><entry namest="col6" nameend="col6" align="center">Test Period 3</entry><entry namest="col7" nameend="col7" align="center"># of Errors Allowed per SIMM</entry></row></thead><tbody valign="top"><row><entry namest="col1" nameend="col1" align="center">1 Mb</entry><entry namest="col2" nameend="col2" align="center">2 hrs</entry><entry namest="col3" nameend="col3" align="center">1</entry><entry namest="col4" nameend="col4" align="center">16 days</entry><entry namest="col5" nameend="col5" align="center">1</entry><entry namest="col6" nameend="col6" align="center">30 days</entry><entry namest="col7" nameend="col7" align="center">2</entry></row><row><entry namest="col1" nameend="col1" align="center">4 Mb</entry><entry namest="col2" nameend="col2" align="center">2 hrs</entry><entry namest="col3" nameend="col3" align="center">1</entry><entry namest="col4" nameend="col4" align="center">11 days</entry><entry namest="col5" nameend="col5" align="center">1</entry><entry namest="col6" nameend="col6" align="center">30 days</entry><entry namest="col7" nameend="col7" align="center">2</entry></row><row rowsep="1"><entry namest="col1" nameend="col1" align="center">16 Mb</entry><entry namest="col2" nameend="col2" align="center">2 hrs</entry><entry namest="col3" nameend="col3" align="center">1</entry><entry namest="col4" nameend="col4" align="center">4 days</entry><entry namest="col5" nameend="col5" align="center">1</entry><entry namest="col6" nameend="col6" align="center">22 days</entry><entry namest="col7" nameend="col7" align="center">2</entry></row></tbody></tgroup></table></tables>
0027If the number of observed errors does not exceed the allowed number of errors during all three test periods, the process will continue with no alert being given. If the number of allowable errors is exceeded for any of the time periods, the system administrator will be alerted by the processor. Based on the severity of the problem, preferably one of two levels of alarms are sent to the system administrator: a Red Flag indicating immediate action required, or a Yellow Flag indicating action required, but suggesting a less urgent requirement, as set out in Table 4 below: <tables id="tabl0004" num="0004"><img file="EP0806726B1_D0002.tif" /></tables>
0028Assuming SIMM type memory components are being used, and since excessive single-bit memory errors can be caused by either a bad SIMM or an improperly seated SIMM, on an alert it may be preferable to first try to re-seat the SIMMs to see if the abnormal error condition repeats before replacing the SIMM.
0029Now referring to Figure 2, a logic flow diagram for the operation of the preferred embodiment of the on-line memory monitoring system of the present invention may be seen. Whenever the ECC circuitry detects a single-bit error, the on-line memory monitoring analysis is initiated. The first test is to check the error log to determine if the same SIMM has given a single-bit error in the last two hours. In the preferred embodiment, the error is maintained as a running log, maintaining the log of the time the error occurred and the SIMM for which it occurred for all single-bit errors for the longest test period used. For the 1 Mb and the 4 Mb devices of Table 3, the log would be maintained to cover the last 30 days. For the 16 Mb devices, the error log would be maintained to cover the last 22 days.
0030Returning again to Figure 2, if the current single-bit error was from a SIMM which gave a single-bit error within the last two hours (test 1 of Table 3), a red flag is sent to the system administrator, indicating a most serious condition caused either by one or more hard errors, or at least an extraordinarily high rate of soft errors.
0031If the SIMM had not failed in the last two hours, a second test is made to see if the SIMM has failed within the time of test period 2 of Table 3, which in the exemplary embodiment will vary dependent upon the DRAM size in question. If there has been another soft error within that time period, a yellow flag is sent to the system administrator, indicating a less serious condition than a red flag, but still indicating single-bit errors have occurred at a statistically very unlikely rate.
0032Finally, if there has been no other soft error for that SIMM during test period 2, a check is made to see if two prior single-bit errors have occurred during the immediately prior test period 3 of Table 3. Here too, if two such soft errors have occurred, a yellow flag is sent to the system administrator so indicating. In any event, on completion of these tests, successful or not, the error log for the SIMM giving the single-bit error will be updated, and sometime during this entire process the corrected data and ECC will be written back to memory on the unverified assumption that the error was a soft error and thus correctable by so doing. Obviously, one could vary the foregoing tests and test periods as desired and/or as appropriate for DRAMs of different soft error rates, the numbers specifically disclosed herein for a preferred embodiment and the number of tests conducted being only exemplary of a particular embodiment of the invention.
0033Thus the on-line memory monitoring system uses a unique statistical inference method previously described based on the number of single-bit memory errors and the frequency of their occurrence as observed by the system provide the appropriate alert.
0034A typical system that may use the present invention may be seen in Figure 3. Here an UltraSPARC processor (CPU), read/write random access memory and system controller are connected through a UPA Interconnect to the SBus to which various peripherals, communication connections and further bus connections are connected. The UPA (Ultra Port Architecture) Interconnect is a cache-coherent, processor-memory interconnect, the precise details of which are not important to the present invention. In the system shown, the error detection and correction circuitry is within the UPA Interconnect (though the ECC circuitry could be elsewhere in the data path to and from the memory, or for that matter the ECC function could be done in software, though this is not preferred because of speed considerations). The UPA Interconnect couples the CPU/memory in the system shown in Figure 3 to an Ethernet connection, and hard disk drives and a CDROM through a SCSI port. It also couples the CPU/memory to a serial port, a floppy disk drive and a parallel port, as well as a number of SBus connectors to which other SBus compatible devices may be connected.
0035The software program for carrying out the operations of the flow chart of Figure 2 normally resides on one of the disk drives in the system. On booting (turn-on) of the system, part of the code is loaded through the UPA Interconnect into the memory. This code causes the CPU to respond to the occurrence of a single-bit error, as flagged and corrected by the ECC circuitry, by calling the rest of the on-line memory monitoring program code into memory and to execute the same to update the error log and to provide the appropriate warning flag to the system administrator.
0036While a preferred embodiment of the present invention has been disclosed and described herein, it will be obvious to those skilled in the art that various changes in form and detail may be made therein without departing from the scope of the invention, which is defined by the appended claims.
Contents3
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US4809276A | Cites | United States of America |
| US5263032A | Cites | United States of America |
| IBM TECHNICAL DISCLOSURE BULLETIN, vol. 12, no. 6, November 1969, NEW YORK, US, page 895 XP002037319 ANONYMOUS: "Error Frequency Warning Detector on Storage with ECC. November 1969." | Non-patent | – |
| IBM TECHNICAL DISCLOSURE BULLETIN, vol. 32, no. 10B, 1 March 1990, page 117 XP000097821 "DOUBLE THRESHOLDING OF ERRORS" | Non-patent | – |
6 members in 4 offices; this record represents the family
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 64431496 | United States of America | A | |
| 644314 | United States of America | – | |
| US19960644314 | – | – | – |
| 644314 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| EP0806726A1 | European Patent Office (EPO) | A1 | |
| JPH1055320A | Japan | A | |
| US5974576A | United States of America | A | |
| EP0806726B1This record | European Patent Office (EPO) | B1 | |
| DE69714507D1 | Germany | D1 | |
| DE69714507T2 | Germany | T2 |
31 legal events, as 3 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Nl: lapsed or anulled due to non-payment of the annual feeLapsedNLV4 | NLV4 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Se: european patent has lapsedLapsedEUG | EUG | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fr: translation filedET | ET | EP | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0806726
- Publication, DOCDB
- 0806726
- Publication, EPODOC
- EP0806726
- Application
- 97106985
- Application, DOCDB
- 97106985
- Application, EPODOC
- EP19970106985
Titles3
- German
- Einrichtung und Verfahren zur On-line-Überwachung von Speichern
- English
- On-line memory monitoring system and methods
- French
- Système et procédé de surveillance en ligne de mémoire
Classification
- CPC, 6
- G06F11/106
- G06F11/076
- G06F11/2205
- G06F11/34
- G06F2201/81
- G06F2201/865
- IPC, 6
- G06F12 16
- G06F11 00
- G06F11 10
- G06F11 22
- G06F11 30
- G06F11 34
Designated states6
- Contracting states, 6
- Germany
- France
- United Kingdom
- Italy
- Netherlands (Kingdom of the)
- Sweden
