Data backup and / or provisioning apparatus and method for data backup and / or data provisioning

EP4602496A1Pending Publication Date: 2025-08-20VALUTIS TECH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023789879
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-10-31
Filing Date
2023-10-09
Publication Date
2025-08-20

AI Technical Summary

Technical Problem

Current data backup solutions lack secure protection against ransomware attacks and efficient methods for analyzing obfuscated data, with homomorphic encryption being computationally intensive and energy-consuming.

Method used

A data backup and provision device utilizing a passivation device with a passivation logic gate to convert digital data into a non-executable form, combined with a reactivation device for secure data retrieval, and a data checking device for malware detection, all integrated with FPGA or ASIC technology for high-performance operations.

Benefits of technology

Provides secure, high-performance data storage that prevents ransomware execution and allows for efficient analysis of obfuscated data without energy-intensive computations, ensuring reliable and convenient data protection and control of machines via the Internet.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

The invention relates to a data backup and / or provisioning apparatus (1) having: at least one passivation device (2) for converting digital original data (4) into digital result data (6), wherein the passivation device has at least one passivation logic gate (8) and wherein the at least one passivation logic gate (8) is configured to convert the digital original data (4) into the digital result data and to generate the result data, wherein the passivation device (2) has a passivation device input interface (10) for supplying the original data to the at least one passivation logic gate (8) and wherein the passivation device (2) has a passivation device output interface (14) for outputting the result data generated by the at least one passivation logic gate (8), wherein the digital original data (4) are defined by a first binary sequence (16), wherein the digital result data are defined by a second binary sequence (18), wherein the first binary sequence (16) and the second binary sequence (18) differ; a reactivation device (80) for converting the result data into target data (22), wherein the reactivation device (80) has a reactivation device input interface (84) for supplying the result data to the reactivation device (80) and preferably a reactivation device output interface (86) for outputting the target data (22), wherein the target data (22) match the original data preferably to at least 90% or to at least 95% or to at least 99% or to at least 99.9% or to exactly 100%.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Data backup and / or provision device and method for data backup and / or data provision The prior art discloses, for example, the following documents illuminating the technical background of the present invention: FPGA based approach for signature based antivirus applications, Guinde, NB; Lohani, RB, Association for Computing Machinery — Feb 25, 2011. E. Nurvitadhi, D. Sheffield, Jaewoong Sim, A. Mishra, G. Venkatesh and D. Marr, "Accelerating Binarized Neural Networks: Comparison of FPGA, CPU, GPU, and ASIC," 2016 International Conference on Field-Programmable Technology (FPT), Xi'an, China, 2016, pp. 77-84, doi: 10.1109 / FPT.2016.7929192. K. Alrawashdeh and C. Purdy, "Ransomware Detection Using Limited Precision Deep Learning Structure in FPGA," NAECON 2018 - IEEE National Aerospace and Electronics Conference, 2018, pp.152-157, doi: 10.1109 / NAECON.2018.8556824. Cilardo, A., Maisto, V., Mazzocca, N., Rocco di Torrepadula, F. (2022). A proposalfor FPGA-Accelerated Deep Learning Ensembles in MPSoC Platforms Applied to Malware Detection. In: Vallecillo, A., Visser, J., Pérez-Castillo, R. (eds) Quality of Information and Communications Technology. QUATIC 2022. Communications in Computer and Information Science, vol 1621. Springer, Cham. https: / / doi.org / 10.1007 / 978-3-031-14179-9_16 The following documents are also known: US9389663B2, US10867078B2, US20170102950A1. In its report "Hype Cycle for Storage and Data Protection Technologies, 2021," published on July 22, 2021, Gardner, Inc., clearly demonstrated that there is no solution that securely protects data backups from ransomware attacks, thus recommending multi-layered solutions. Gardner, Inc. introduced the term "cyberstorage." Approaches published in this regard can be found, for example, in the following publications: US2022 / 0156395A1, US2023032139A1, US2022156396A1, US2023153438A1, US2023141909A1, WO2023076089A1, US11632394B1,KR20230042840A, US20190207969A1, US2021286884A1. Furthermore, the following publications demonstrate methods for homomorphic data analysis: GR Thompson and LA Flynn, "Polymorphic malware detection and identification via context-free grammar homomorphism," in Bell Labs Technical Journal, vol. 12, no. 3, pp. 139–147, Fall 2007, doi: 10.1002 / bltj.20256. Mercy Joseph and Gobi Mohan, “Design a hybrid Optimization and Homomorphic Encryption for Securing Data in a Cloud,” in International Journal of Computer Networks and Applications (IJCNA), Volume 9, Issue 4, July–August (2022), DOI: 10.22247 / ijcna / 2022 / 214502. Liam Morris, “Environment Analysis of Partially and Fully Homomorphic Encryption”, Department of Computer Science, Rochester Institute of Technology, Rochester, New York, May 10, 2013. Further publications dealing with homomorphic data include: US2023291541A1, US2023291573A1, US2023188343A1, WO2023158193A1. Furthermore, the following publicationsMethoden zum Obfuskieren von Daten gezeigt: Protecting Software through Obfuscation: Can It Keep Pace with Progress in Code Analysis?; ACM Computing Surveys; Volume 49; Issue 1; Article No.: 4pp 1–37; https: / / doi.org / 10.1145 / 2886012; 05.04.2016. S. K. Udupa, S. K. Debray and M. Madou, "Deobfuscation: reverse engineering obfuscated code," 12th Working Conference on Reverse Engineering (WCRE'05), Pittsburgh, PA, USA, 2005, pp.10 pp.-54, doi: 10.1109 / WCRE.2005.13. Sebastian Banescu, Christian Collberg, Vijay Ganesh, Zack Newsham, and Alexander Pretschner.2016. Code obfuscation against symbolic execution attacks. In Proceedings of the 32nd Annual Conference on Computer Security Applications (ACSAC '16). Association for Computing Machinery, New York, NY, USA, 189–200. https: / / doi.org / 10.1145 / 2991079.2991114. B. Yadegari, B. Johannesmeyer, B. Whitely and S. Debray, "A Generic Approach to Automatic Deobfuscation of Executable Code," 2015 IEEE Symposium on Security and Privacy, San Jose, CA,USA, 2015, pp.674-691, doi: 10.1109 / SP.2015.47. Viticchié et al., "Assessment of Source Code Obfuscation Techniques," 2016 IEEE 16th International Working Conference on Source Code Analysis and Manipulation (SCAM), Raleigh, NC, USA, 2016, pp.11-20, doi: 10.1109 / SCAM.2016.17. You and K. Yim, "Malware Obfuscation Techniques: A Brief Survey," 2010 International Conference on Broadband, Wireless Computing, Communication and Applications, Fukuoka, Japan, 2010, pp.297-300, doi: 10.1109 / BWCCA.2010.85. Hada, S. (2000). Zero-Knowledge and Code Obfuscation. In: Okamoto, T. (eds) Advances in Cryptology — ASIACRYPT 2000. ASIACRYPT 2000. Lecture Notes in Computer Science, vol 1976. Springer, Berlin, Heidelberg. https: / / doi.org / 10.1007 / 3-540-44448-3_34. Code Obfuscation Literature Survey; Arini Balakrishnan, Chloe Schulze; CS701 Construction of Compilers, Instructor: Charles Fischer; Computer Sciences Department University of Wisconsin, Madison; December 19th, 2005. Weitere Schriften, die sich mitReferences dealing with obfuscated data include: US2023259613A1, US2023262032A1, US2023239144A1. Furthermore, the following publications describe OCR analyses: Algorithms and methods for document-specific analysis of historical and OCR-captured texts, Ulrich Reffle, October 24, 2011, ISBN-13: 978-3843901062. Full text via OCR – possibilities and limits, Maria Federbusch, Christian Polzin, 2013, ISBN 978-3-88053-185-7. OCR ACCURACY IMPROVEMENT ON DOCUMENT IMAGES THROUGH A NOVEL PRE-PROCESSING APPROACH, A. El Harraj and N. Raissouni, Signal & Image Processing: An International Journal (SIPIJ) Vol.6, No.4, August 2015, DOI: 10.5121 / sipij.2015.64011. OCR Based Thresholding, Yves Rangoni, Faisal Shafait, Thomas M. Breuel. Going Grey? Comparing the OCR Accuracy Levels of Bitonal and Greyscale Images, Tracy Powell, Gordon Paynter, ISSN 1082-9873. Adaptive Thresholding for OCR: A Significant Test Ray Smith, Chris Newton, Phil Cheatle Personal Systems Laboratory HP Laboratories BristolHPL-93-22 March, 1993. Binarization Techniques used for Grey Scale Images, Puneet, Garg, International Journal of Computer Applications (0975 – 8887), Volume 71– No.1, June 2013. Ferner werden durch die folgenden Dokumente Mustererkennungen beschrieben: J. -S. Luo and D. C. -T. Lo, "Binary malware image classification using machine learning with local binary pattern," 2017 IEEE International Conference on Big Data (Big Data), Boston, MA, USA, 2017, pp.4664-4667, doi: 10.1109 / BigData.2017.8258512. D. Kothari, M. Patel and A. K. Sharma, "Implementation of Grey Scale Normalization in Machine Learning & Artificial Intelligence for Bioinformatics using Convolutional Neural Networks," 20216th International Conference on Inventive Computation Technologies (ICICT), Coimbatore, India, 2021, pp.1071-1074, doi: 10.1109 / ICICT50816.2021.9358549. E. R. Urbach, J. B. T. M. Roerdink and M. H. F. Wilkinson, "Connected Shape-Size Pattern Spectra for Rotation and Scale-Invariant Classification ofGray-Scale Images," in IEEE Transactions on Pattern Analysis and Machine Intelligence, vol.29, no.2, pp.272-285, Feb. 2007, doi: 10.1109 / TPAMI.2007.28. T. Ojala, M. Pietikainen and T. Maenpaa, "Multiresolution gray-scale and rotation invariant texture classification with local binary patterns," in IEEE Transactions on Pattern Analysis and Machine Intelligence, vol.24, no.7, pp.971-987, July 2002, doi: 10.1109 / TPAMI.2002.1017623. Riesen, K., Bunke, H. (2008). Pattern Recognition. SSPR / SPR 2008. Lecture Notes in Computer Science, vol 5342. Springer, Berlin, Heidelberg. https: / / doi.org / 10.1007 / 978-3-540-89689-0_33 Furthermore, with patent application PCT / EP2022 / 059665, the applicant of the present patent application filed a patent application for a technology that uses an analog interface to create a barrier thatcannot be overcome by malware. The subject matter of PCT / EP2022 / 059665 can be combined with the subject matter of the present invention. In particular, control signals can be effected in the system according to the present invention according to one or more subject matters of PCT / EP2022 / 059665. The subject matter of PCT / EP2022 / 059665 is hereby incorporated by reference in its entirety into the subject matter of the present document. The object of the present invention is to provide a reliable and preferably high-performance possibility for storing data securely and preferably conveniently. Additionally or alternatively, the present invention is intended to create a possibility for making email communication secure and convenient. Additionally or alternatively, the present invention is intended to create a possibility for controlling machines, in particular robots, vehicles, systems, or parts thereof, securely and conveniently via the Internet. The aforementioned object isAccording to the invention, this object is achieved by a data backup device, in particular a data backup and provision device, according to claim 1. A data backup and / or provision device according to the invention preferably comprises at least: A passivation device for converting digital original data into digital result data, wherein the passivation device comprises at least one passivation logic gate and wherein the at least one passivation logic gate is configured to convert the digital original data into the digital result data and to generate the result data, wherein the passivation device comprises a passivation device input interface for supplying the original data to the at least one passivation logic gate and wherein the passivation device comprises a passivation device output interface for outputting the result data generated by the at least one passivation logic gate, wherein thedigital original data are preferably defined by a first binary sequence, wherein the digital result data are preferably defined by a second binary sequence, wherein the first binary sequence and the second binary sequence are particularly preferably different from one another. Furthermore, the data backup and / or provision device preferably has a reactivation device for converting the result data into target data, wherein the reactivation device has a reactivation device input interface for supplying the result data to the reactivation device and preferably a reactivation device output interface for outputting the target data, wherein the target data preferably correspond to the original data by at least 90% or at least 95% or at least 99% or at least 99.9% or exactly 100%. Result data are preferably stored as a result data file. This embodiment is particularly suitable because it allows the systemSent malicious code is no longer executable and thus cannot cause any damage to the system until reactivated. The data backup and / or provision device according to the invention can also be referred to as "cyberstorage" in the sense of the definition by "Gardner, Inc." described above. Furthermore, this type of storage particularly preferably obfuscates the data, whereby malicious code contained therein is deactivated or rendered non-executable. In addition, the data stored in this way can preferably still be analyzed without the data or the potentially contained malicious code being rendered executable again; consequently, data stored according to the present invention can exhibit homomorphic properties. Homomorphic encryption has the major disadvantage that very complex mathematical operations must be executed, resulting in a high time requirement, high computational effort, and consequently high energy consumption.The analyzability of obfuscated data creates a significantly more efficient way of storing data in a non-executable manner on the one hand, and of analyzing it securely on the other. According to a preferred embodiment of the present invention, the passivation device input interface for forwarding digital signals is connected to the passivation device output interface exclusively via the at least one passivation logic gate. This embodiment is particularly suitable because no further connections need to be secured against unauthorized access. According to a preferred embodiment of the present invention, the passivation device, in particular at least the passivation logic gate, is at least part of a data backup and provision device - logic gate device, in particular Field Programmable Gate Array (FPGA) or Application Specific Integrated Circuit (ASIC) or ComplexProgrammable Logic Device (CPLD) or Simple Programmable Logic Device (SPLD). This design is particularly suitable because the components used are especially suitable for executing redundant processes and are very fast. According to a preferred embodiment of the present invention, a buffer device is provided. According to a preferred embodiment of the present invention, the buffer device has a buffer device data memory for storing the result data. This design is particularly suitable because the buffer device data memory allows the result data to be transferred directly to further process steps without having to be stored again in another, possibly permanent, memory. According to a preferred embodiment of the present invention, the passivation device output interface is connected to a buffer device input interface of the buffer device. ThisThis embodiment is particularly suitable because this connection enables the direct transfer of data from the passivation device to the holding device. According to a preferred embodiment of the present invention, the holding device input interface is connected to the holding device data memory, and a holding device output interface of the holding device is provided, wherein the holding device output interface is connected to the holding device data memory. The fact that the holding device input interface is connected to the holding device data memory means that the data introduced via the holding device input interface can be fed directly or indirectly to the holding device data memory. This embodiment is particularly suitable because this connection enables the result data to be sent to the holding device data memory. According to a preferredIn a preferred embodiment of the present invention, result data stored by the data processing device of the provision device in the provision device data memory of the provision device can be forwarded to the reactivation device, in particular via a bidirectional or unidirectional data connection, in particular by means of at least or exactly one optical fiber. This embodiment is particularly suitable because forwarding the result data, for example, via an optical fiber to the reactivation device enables particularly fast transmission of the data to the reactivation device. According to a preferred embodiment of the present invention, the provision device has a provision device communication interface, wherein the provision device communication interface is connected to the work system or theControl device for transmitting status data of the provisioning device. This design is particularly suitable because the separate communication interface allows the unidirectional transmission of status data independent of other data transmission. The status data preferably includes the memory utilization, the performance utilization, the number of files stored in the provisioning device data memory and / or the names of the files stored in the provisioning device data memory and / or documentation of executed commands. This design is particularly suitable because the status data thus provides information about the ongoing processes and resources used. According to a preferred embodiment of the present invention, the passivation device and the provisioning device are part of a passivation and provisioning unit. This design is particularly suitable because by combining theUnits, resources can be saved or shared, and even faster data exchange can take place through internal interfaces. According to a preferred embodiment of the present invention, the passivation device output interface is connected to a holding unit data memory of the passivation and holding unit for supplying the input data. This embodiment is particularly suitable because the connection allows the data to be written directly from the passivation unit into the memory. According to a preferred embodiment of the present invention, a holding unit output interface of the passivation and holding unit is provided, wherein the holding unit output interface is connected to the holding unit data memory. This embodiment is particularly suitable because the connection enables the data to be stored in the holding unit data memory after passing through the holding device.In a preferred embodiment of the present invention, result data stored in the retention unit data memory of the passivation and retention unit can be forwarded by a data processing device of the passivation and retention unit to the reactivation device, in particular via a bidirectional or unidirectional data connection, in particular by means of at least or precisely one optical fiber. This means that the data processing device of the passivation and retention unit is configured to forward result data stored in the retention unit data memory of the passivation and retention unit to the reactivation device. This embodiment is particularly suitable because the data processing device can take over processes that do not necessarily have to be carried out by the other components of the passivation or retention unit. According to a preferred embodiment of the present invention, aA data verification device is provided for detecting malware. This embodiment is particularly suitable because the data verification device can already detect malware within the device. The data verification device preferably has a data verification device input interface for feeding the result data to a data processing device of the data verification device for detecting malware in the result data. This embodiment is particularly suitable because the separate input interface can be configured exclusively for feeding the data to the data verification device. The data verification device preferably has a data verification device output interface for outputting the result data checked by the data processing device of the data verification device and / or for outputting a verification result. This embodiment is particularlysuitable, since the data can be transferred to further devices via this interface after verification. According to a preferred embodiment of the present invention, the data verification device input interface for forwarding digital signals and / or data is preferably connected to the data verification device input interface exclusively via the data processing device of the data verification device. According to a preferred embodiment of the present invention, the data verification device has at least one CPU and / or GPU as a data processing device. This embodiment is particularly suitable, since a CPU or GPU is suitable for executing common methods for verifying data. According to a preferred embodiment of the present invention, the data verification device is designed as a processor device for controlling the functions of the data verification device and / or for effectinga data exchange with at least one further device, in particular a work system and / or a control system and / or a data backup and provision device logic gate device and / or the passivation device and / or the retention device and / or a passivation and retention unit. The control system can be designed as an intermediate device or communication device between the work system and the data backup and / or provision device. This embodiment is particularly suitable because it enables direct triggering of control functions based on the results determined in the data verification device. According to a preferred embodiment of the present invention, the data verification device has at least one data verification logic gate as a data processing device, and wherein the at least one data verification logic gate is configured to detectof malware in the result data. This embodiment is particularly suitable because, due to its nature, the logic gate used can only carry out the data check it requires, thus preventing any opportunity for malware to attack. According to a preferred embodiment of the present invention, the data checking device input interface is connected to the data checking device output interface exclusively via the at least one data checking logic gate for forwarding digital signals. This means that the digital result data is processed or checked by at least one data checking logic gate before it reaches the data checking device output interface. This embodiment is particularly suitable because it ensures that the digital result data must have passed through a data checking logic gate at least once before it reaches the output interface.According to a preferred embodiment of the present invention, the data verification logic gate sends a signal to the retention device or the passivation and retention unit depending on a verification result of the result data, in particular of the concrete result data file, and the retention device or the passivation and retention unit identifies the result data, in particular the concrete result data file, as contaminated or non-contaminated or assigns it to a memory area provided for contaminated result data, in particular contaminated result data files, or assigns it to a memory area provided for non-contaminated result data, in particular contaminated result data files. Contaminated in the context of the present invention means that code representing malware is part of the respective data. Malware can be, among other things, Trojans, in particularEncryption Trojans, and / or viruses. This embodiment is particularly suitable because result data that has already been positively checked for known malicious code is isolated and cannot reach the other units independently. According to a preferred embodiment of the present invention, the data processing device of the data checking device has at least one data checking logic gate, wherein the data checking device has a data checking device data memory, wherein malware representative data is provided in the data checking device data memory. This embodiment is particularly suitable because this malware representative data can be used for partial or complete comparison with the result data by the data processing device or the data checking device. According to a preferred embodiment of the present invention, the malware representative data isan update device. This embodiment is particularly suitable because it allows the stored malware representation data to be supplemented with newly detected malware representation data. The update device can be supplied with updates directly from a server device or indirectly via the control device and / or the work system. The update supply is preferably encrypted and the updates are particularly preferably stored on a data storage device or part of a data storage device that is technically, in particular physically, separated from the remaining data storage devices, i.e., is not directly connected to one another. According to a preferred embodiment of the present invention, the malware representation data of a piece of malware has a malware representation data binary sequence, wherein the malware representation data binary sequence is different from the binary sequence of the malware. This embodiment isparticularly suitable, since no actual malware can be generated from the malware representation data. According to a preferred embodiment of the present invention, the malware representation data binary sequence is longer than the binary sequence of the malware, in particular the malware representation data binary sequence is at least by a factor of 1.2 or a factor of 1.6 or a factor of 2 or a factor of 4 or a factor of 8 longer than the binary sequence of the malware. Additionally or alternatively, according to a preferred embodiment of the present invention, all contiguous bit sequences of the binary sequence of the malware with a length of at least 0.001%, in particular at least 1% or preferably at least 10% or most preferably at least 20%, of the total length of the binary sequence of the malware of all contiguous bit sequences of the malware representation data binary sequence with a length of at least 0.001%, in particular at least 1% or preferablyat least 10% or most preferably at least 20% of the total length of the malware binary sequence. Additionally or alternatively, according to a preferred embodiment of the present invention, contiguous bit sequences of the malware binary sequence with a length of at least 32 bits, in particular at least 64, at least 128, at least 256, or at least 512 bits, are different from all contiguous bit sequences of the malware representative data binary sequence with a length of at least 32 bits, in particular at least 64, at least 128, at least 256, or at least 512 bits. This embodiment is particularly suitable because it prevents actual malware and also no malicious code parts from being generated from the malware representative data. According to a preferred embodiment of the present invention, the data verification logic gate is connected to the data verification device data memory for data purposes, in particular for reading purposes.This embodiment is particularly suitable because it allows a check to be performed directly from the memory using logic gates. According to a preferred embodiment of the present invention, the data checking device data memory has at least one lookup table, wherein the lookup table has malware representation data for several malware programs. This embodiment is particularly suitable because the table provides the malware representation data in a structured form for the data checking device. According to a preferred embodiment of the present invention, the data checking device is configured to perform a comparison of the malware representation data and the result data. This embodiment is particularly suitable because the data checking device can thus recognize known malware in the result data. According to a preferred embodiment of the present invention, the binary sequence of the original data is according to afirst logic into the result data and the malware representation data can be generated from the bit sequences of the malware according to the first logic. This embodiment is particularly suitable because neither the original data nor the malware representations are present in the original bit sequence and are executable. According to a preferred embodiment of the present invention, the result data preferably represent machine-readable character encoding. According to a preferred embodiment of the present invention, the character encoding is preferably a 2-bit character encoding or a 3-bit character encoding or a 4-bit character encoding or a more than 4-bit, in particular 7, 8 or 18-bit character encoding, in particular American Standard Code for Information Interchange (ASCII) or Indian Script Code for Information Interchange (ISCII) or Tamil Script Code for Information Interchange (TSCII). This embodiment is particularly suitable because the use of readableCharacters in the result data enable easy translation. According to a preferred embodiment of the present invention, the result data preferably represent color values ​​and / or brightness values. This embodiment is particularly suitable because a very high data transmission rate can be achieved due to the high number of values ​​separated from one another. According to a preferred embodiment of the present invention, the malware representation data preferably represent a machine-readable character encoding. According to a preferred embodiment of the present invention, the character encoding is preferably a 2-bit character encoding or at least a 2-bit character encoding or a 3-bit character encoding or a 4-bit character encoding or at least a 4-bit character encoding or a more than 4-bit, in particular 7, 8 or 18-bit character encoding, in particular American Standard Code for Information Interchange (ASCII) or Indian Script Code forInformation Interchange (ISCII) or Tamil Script Code for Information Interchange (TSCII). This embodiment is particularly suitable because the use of readable characters enables a character-by-character comparison of the malware representation data with the result data. According to a preferred embodiment of the present invention, the malware representation data represents color values ​​and / or brightness values. This embodiment is particularly suitable because, in addition to the character-by-character comparison, an optical comparison of the malware representation data with the result data can also be carried out. According to a preferred embodiment of the present invention, the result data can be deleted in the event that the presence of malware or a defined group of malware or a defined probability for the presence of malware can be determined based on the check result. This embodiment is particularly suitable because, in the case of a confirmed infection of theResult data with already known malware makes further use or storage unnecessary. According to a preferred embodiment of the present invention, the data verification device has a data verification communication interface, wherein the data verification communication interface is connected to the work system or the control device by means of a unidirectional data connection, in particular by means of at least or exactly one optical fiber, for transmitting status data of the data verification device. This embodiment is particularly suitable because the work system or the control device can thus be informed about the status of the submitted data and the processing system without any data transmission taking place beyond the status data. The status data preferably includes the memory utilization, the performance utilization, the number of files held in the data verification device data memoryand / or the names of the files stored in the data checking device data memory and / or documentation of executed commands. This embodiment is particularly suitable because the specified parameters in the structure of the status data prevent any further unauthorized data from being transmitted. According to a preferred embodiment of the present invention, the data checking device, in particular at least the data checking logic gate, is part of the data backup and provision device logic gate device, in particular a Field Programmable Gate Array (FPGA) or Application Specific Integrated Circuit (ASIC) or Complex Programmable Logic Device (CPLD) or Simple Programmable Logic Device (SPLD). This embodiment is particularly suitable because the implementation of the data checking device on a logic gate optimally utilizes its strength in the redundant implementation of complex logic. According to a preferredIn one embodiment of the present invention, the data verification device is part of a data verification unit. According to a preferred embodiment of the present invention, a data verification unit output interface of the data verification unit is connected to a reactivation device input interface of the reactivation device. According to a preferred embodiment of the present invention, a retention unit output interface of the passivation and retention unit is connected to the data verification device input interface for transmitting the result data. According to a preferred embodiment of the present invention, a retention unit output interface of the passivation and retention unit is directly connected to the data verification device input interface. According to a preferred embodiment of the present invention, a retention unit output interface of the passivation andRetention unit is connected directly to the data verification device input interface via a unidirectional conductor, in particular optical fiber. According to a preferred embodiment of the present invention, a retention device output interface of the retention device is connected to the data verification device input interface for transmitting the result data. According to a preferred embodiment of the present invention, a retention device output interface of the retention device is connected directly to the data verification device input interface. According to a preferred embodiment of the present invention, a retention device output interface of the retention device is connected directly to the data verification device input interface via a unidirectional conductor, in particular optical fiber. According to a preferred embodiment of the present invention, theData checking device is a component of the retention device or the passivation and retention unit. This embodiment is particularly suitable since the combination of the various devices on one logic gate maximizes the transmission speed, especially between the individual devices. According to a preferred embodiment of the present invention, the reactivation device has at least one data processing device, and wherein the at least one data processing device is configured to convert the digital result data into the digital target data. According to a preferred embodiment of the present invention, the reactivation device input interface is preferably connected exclusively via the data processing device to the reactivation device output interface for forwarding digital signals. According to a preferred embodiment of the present invention, theThe reactivation device comprises at least one CPU and / or GPU as a data processing device, and wherein the at least one CPU and / or GPU is configured to convert the digital result data into the digital target data. According to a preferred embodiment of the present invention, the target data can be executed and / or analyzed by the data processing device of the reactivation device in a sandbox. According to a preferred embodiment of the present invention, the reactivation device input interface is connected to a data processing device of the reactivation device, in particular a reactivation logic gate, and / or a reactivation device data memory of the reactivation device, wherein the result data can be converted into the target data and / or analyzed for malware by the data processing device of the reactivation device. According to a preferred embodimentAccording to the present invention, the reactivation device data memory is formed by at least one first reactivation device data memory and a second reactivation device data memory, wherein the first reactivation device data memory and the second reactivation device data memory are connected to one another in terms of data technology exclusively via at least one unidirectionally acting element, in particular the reactivation logic gate. This means that the target data, even if they contain malware, does not have a return channel from the second reactivation device data memory to the first reactivation device data memory for manipulating the data stored on the first reactivation device data memory. According to a preferred embodiment of the present invention, the reactivation device has at least one reactivation logic gate as a data processing device, and wherein the at least oneReactivation logic gate is configured to convert the digital result data into the digital target data. According to a preferred embodiment of the present invention, the reactivation device input interface is connected to the reactivation device output interface for forwarding digital signals exclusively via the at least one reactivation logic gate. According to a preferred embodiment of the present invention, the first reactivation device data memory for providing the result data is functionally arranged before the reactivation logic gate, and the second reactivation device data memory is functionally arranged after the reactivation logic gate for storing the target data. The first reactivation device data memory and the second reactivation device data memory can be physically separate data memories or a data memory with physically separateseparate partitions. According to a preferred embodiment of the present invention, the reactivation device can comprise a CPU and / or GPU or at least one CPU and / or GPU if the data processing device is the at least one reactivation logic gate, wherein the CPU and / or GPU is configured to execute and / or analyze the target data in a sandbox, in particular to analyze it for malware. According to a preferred embodiment of the present invention, the reactivation device comprises an update device for updating malware identification data, wherein the CPU and / or GPU is configured to analyze the target data using updated malware identification data. According to a preferred embodiment of the present invention, the reactivation device comprises a reactivation device communication interface, wherein theThe reactivation device communication interface is connected to the work system or the control device by means of a unidirectional data connection, in particular by means of at least one or exactly one optical fiber, for transmitting status data of the reactivation device. The status data preferably includes the memory utilization, the power utilization, the number of files stored in the reactivation device data memory and / or the names of the files stored in the reactivation device data memory and / or documentation of executed commands. According to a preferred embodiment of the present invention, the reactivation device, in particular at least the reactivation logic gate, is part of the data backup and provision device logic gate device, in particular a Field Programmable Gate Array (FPGA) or Application-Specific Integrated Circuit (ASIC) or Complex Programmable Logic Device.(CPLD) or Simple Programmable Logic Device (SPLD). According to a preferred embodiment of the present invention, the retention device output interface is connected to the reactivation device input interface. According to a preferred embodiment of the present invention, a retention unit output interface of the passivation and retention unit is connected to the reactivation device input interface for transmitting the result data. According to a preferred embodiment of the present invention, a retention unit output interface of the passivation and retention unit is directly connected to the reactivation device input interface. According to a preferred embodiment of the present invention, a retention unit output interface of the passivation and retention unit is directly connected to the reactivation device input interface via a unidirectional conductor, in particular an optical fiber.According to a preferred embodiment of the present invention, a holding device output interface of the holding device is connected to the reactivation device input interface for transmitting the result data. According to a preferred embodiment of the present invention, a holding device output interface of the holding device is directly connected to the reactivation device input interface. According to a preferred embodiment of the present invention, a holding device output interface of the holding device is directly connected to the reactivation device input interface via a unidirectional conductor, in particular an optical fiber. According to a preferred embodiment of the present invention, a data verification device output interface of the data verification device is connected to the reactivation device input interface for transmitting the result data.connected. According to a preferred embodiment of the present invention, a data verification device output interface of the data verification device is directly connected to the reactivation device input interface. According to a preferred embodiment of the present invention, a data verification device output interface of the data verification device is directly connected to the reactivation device input interface via a unidirectional conductor, in particular an optical fiber. According to a preferred embodiment of the present invention, a data verification unit output interface of the data verification unit is connected to the reactivation device input interface for transmitting the result data. According to a preferred embodiment of the present invention, a data verification unit output interface of the data verification unit is directly connected to theReactivation device input interface. According to a preferred embodiment of the present invention, a data verification unit output interface of the data verification unit is connected directly to the reactivation device input interface via a unidirectional conductor, in particular an optical fiber. According to a preferred embodiment of the present invention, a retention device control logic gate part is provided. According to a preferred embodiment of the present invention, the retention device control logic gate part is configured to convert original retention device control data into retention device control result data. According to a preferred embodiment of the present invention, a retention device control data output is provided for outputting the retention device control result data. According to a preferred embodiment of the present invention, theOriginal reserve device control data can be provided by the work system or the control device. According to a preferred embodiment of the present invention, a reactivation device control logic gate part is provided. According to a preferred embodiment of the present invention, the reactivation device control logic gate part is configured to convert original reactivation device control data into reactivation device control result data. According to a preferred embodiment of the present invention, a reactivation device control data output is provided for outputting the reactivation device control result data. According to a preferred embodiment of the present invention, a reactivation device control data input is provided for supplying the reactivation device control original data. According to a preferred embodiment of the present invention, theOriginal reactivation device control data can be provided by the work system or the control device. According to a preferred embodiment of the present invention, a data checking device control logic gate part is provided. According to a preferred embodiment of the present invention, the data checking device control logic gate part is configured to convert original data checking device control data into data checking device control result data. According to a preferred embodiment of the present invention, a data checking device control data output is provided for outputting the data checking device control result data. According to a preferred embodiment of the present invention, a data checking device control data input is provided for supplying the data checking device control original data. According to a preferred embodiment of the present invention, theData checking device control source data can be provided by the work system or the control device. The above-mentioned object is additionally or alternatively also achieved by a control system for controlling at least one digital subsystem via a network, in particular the Internet, wherein the digital subsystem has a data input interface, wherein the data input interface is connected to the network on the one hand and to a control logic gate on the other hand, wherein the control logic gate is configured to generate defined control signals or control data depending on control source data supplied to the data input interface via the network, wherein the bit sequence of the control source data is preferably different from the bit sequence of the control signals or control data. According to a preferred embodiment of the present invention, the digital subsystem has at least one unidirectionalData line channel, in particular an optical fiber, for outputting status data. According to a preferred embodiment of the present invention, control data for controlling the subsystem can be supplied to the subsystem exclusively via the control logic gate. According to a preferred embodiment of the present invention, the status data can be output to the network exclusively via the unidirectional data line channel. According to a preferred embodiment of the present invention, the subsystem is a robot or a robot device. According to a preferred embodiment of the present invention, the subsystem is a router, in particular a network router, in particular an internet router. According to a preferred embodiment of the present invention, the subsystem is a vehicle, in particular a car or a truck or an aircraft or a construction vehicle, in particular an excavator or a concrete mixer truck or a bulldozer, or aHelicopter or a boat or a two-wheeler, in particular a motorcycle or scooter or a bicycle, in particular an e-bike, or a rail-bound vehicle, in particular a train. According to a preferred embodiment of the present invention, the subsystem is one or more actuators, in particular motor(s), in particular electrically and / or pneumatically and / or hydraulically and / or by means of combustion processes operable motors, and / or one or more water supply facilities and / or a factory, in particular for the production of basic chemicals, refinery or waste incineration or food production or drug / vaccine production, or several factories and / or a medical device 148 or several medical devices and / or a communication device or several communication devices and / or an energy supply facility, in particular solar power plant, coal-fired power plant, wind power plant, gas power plant, nuclear power plant,Hydroelectric power plant or tidal power plant, or several energy supply devices and / or a production device, in particular an industrial robot, or several production devices. According to a further preferred embodiment of the present invention, the control system according to the invention has a passivation system for converting digital control source data into digital control result data. The passivation system can be found, for example, in patent application PCT / EP2022 / 059665 and is described in detail therein. According to the present invention, it is used to form an additional or alternative communication channel for controlling the respective function processor device and / or for transmitting status data to the work system or a control device. The digital control result data preferably represent the digital control source data in a non-executable state and are used forControlling the function processor device, wherein the digital control source data represents a bit combination of digital source data, in particular a digital file or a digital data stream. Preferably, at least one control data processing processor is provided for generating a plurality of different analog signals of a control representation type depending on digital control source data, wherein the digital control source data represents a plurality of different input commands from at least one input device, wherein the plurality of different input commands of the digital control source data are represented by a plurality of different analog signals of the control representation type, wherein the plurality of different analog signals of the control representation type are preferably generateable in a plurality of, in particular at least four, different states, wherein a plurality of or each analog signalof the control representation type of the plurality of different analog signals of the control representation type represents a defined input command, in particular directly or indirectly, wherein the control data processing processor has at least one data interface for receiving the digital control source data, wherein the control data processing processor has at least one signal output for outputting the analog signals of the control representation type, a control input signal processing processor for converting the analog signals of the control representation type into the digital result control data for manipulating the digital control result data, wherein the control input signal processing processor has at least one signal input for receiving the analog signals of the control representation type output via the at least one signal output of the control data processing processor, wherein the digital control result data is a digitalRepresentation of at least some of the analog signals of the control representation type, wherein the control input signal processing processor is coupled at least indirectly to a function processor device for executing or effecting at least one function and preferably a plurality of functions. According to a further preferred embodiment of the present invention, the control of the function processor device for executing at least one defined function and preferably a plurality of different functions can be effected depending on the digital control result data. According to a further preferred embodiment of the present invention, the digital control result data can be generated for defined analog signals of the control representation type. According to a further preferred embodiment of the present invention, the defined analog signals of the control representation type are of the defined function or thedefined functions of the function processor device or represent them. According to a further preferred embodiment of the present invention, a function output signal processing processor is provided for generating a plurality of different analog signals of the function processing type for mapping the control of the function processor device. According to a further preferred embodiment of the present invention, the plurality of different analog signals can be generated in at least four mutually different states. According to a further preferred embodiment of the present invention, a function data processing processor is provided for generating visualization data for visualizing a function processor control visualization, in particular a function processor control mask. According to a further preferred embodiment of the present invention, the function processor control visualizationas a function processor control mask. According to a further preferred embodiment of the present invention, the function processor control visualization can be generated at least partially as a function of the analog signals of the function processing type generated by the function output signal processing processor. According to a further preferred embodiment of the present invention, manipulation of the function processor control visualization can be effected by the at least one input device. According to a further preferred embodiment of the present invention, the digital control source data can be generated as a function of the manipulation of the function processor control visualization. According to a further preferred embodiment of the present invention, the function processor control visualization and the control data processing processor are connected to one another at least indirectly via the data interface. According to aAccording to a further preferred embodiment of the present invention, the plurality of different analog signals of a bit-component combination representation type comprises at least four different analog signals of the bit-component combination representation type. According to a further preferred embodiment of the present invention, the plurality of different analog signals of the bit-component combination representation type comprises at least thirty-two different analog signals of the bit-component combination representation type. According to a further preferred embodiment of the present invention, the control source data processing processor for generating the plurality of different analog signals of the bit-component combination representation type has at least one signal output, wherein the signal output can be supplied with a plurality of different combinations of at least voltage and current. According to a further preferred embodiment of the present invention,the different combinations of at least voltage and current are analog individual signals or modulated multiple signals. According to a further preferred embodiment of the present invention, the control source data processing processor has a plurality of independently controllable signal outputs for generating the plurality of different analog signals of the bit-part combination representation type, wherein at least several signal outputs from the control source data processing processor can each be supplied with a plurality of different combinations of voltage and current. According to a further preferred embodiment of the present invention, a plurality of different combinations of voltage and current per signal output comprises at least sixteen combinations. According to a further preferred embodiment of the present invention, a plurality of different combinations of voltage and currentat least thirty-two different combinations per signal output. According to a further preferred embodiment of the present invention, at least several of the independently controllable signal outputs can be controlled simultaneously to generate one analog signal each, or at least several of the independently controllable signal outputs can be controlled simultaneously to generate a modulated analog signal. According to a further preferred embodiment of the present invention, the digital control result data has a control result data format and the digital source data has a source data format, wherein the source data format and the control result data format are different. According to a further preferred embodiment of the present invention, the input signal processing processor has at least one input signal processing processor output for outputting the digital control result data. According toAccording to a further preferred embodiment of the present invention, the input signal processing processor output is coupled to a storage medium for digitally storing the digital control result data. According to a further preferred embodiment of the present invention, there is preferably no digital data connection for transmitting digital control source data between the storage medium and the control source data processing processor. According to a further preferred embodiment of the present invention, the input signal processing processor and the control source data processing processor are arranged on a circuit board. According to a further preferred embodiment of the present invention, the path of the analog signals of the bit-part combination representation type from the control source data processing processor to the input signal processing processor is shorter than 100 cm or shorter than 20 cm or shorter than 50 mm or shorter than10mm or shorter than 5mm. According to a further preferred embodiment of the present invention, the control source data is / are original reactivation device control data and / or original data checking device control data and / or original retention device control data, wherein in this case, these data are not generated by a logic gate, but result from the analog signals. According to a further preferred embodiment of the present invention, the control result data is / are data checking device control result data and / or retention device control result data and / or reactivation device control result data. According to a further preferred embodiment of the present invention, the function processor device is / are the data checking device and / or retention device and / or the reactivation device and / or the logic gate device, in particular according to claim 86. The above-mentioned object isAdditionally or alternatively, this is achieved by a logic gate device, in particular an FPGA device, in particular precisely one FPGA. The logic gate device preferably comprises: at least one passivation logic gate part, wherein the at least one passivation logic gate part is configured to convert digital original data into digital result data, wherein the result data represents a passivated form of the original data. Passivated here means that the result data cannot be executed correspondingly with respect to the original data. According to a preferred embodiment of the present invention, a hold device data supply output is provided for outputting the result data to a hold device. According to a preferred embodiment of the present invention, the logic gate device preferably comprises a hold device control logic gate part. According to a preferred embodiment of the present invention, theA retention device control logic gate part is configured to convert original retention device control data into retention device control result data. According to a preferred embodiment of the present invention, a retention device control data output is provided for outputting the retention device control result data. According to a preferred embodiment of the present invention, the logic gate device preferably comprises a reactivation logic gate part. According to a preferred embodiment of the present invention, the reactivation logic gate part is configured to convert the result data into target data. According to a preferred embodiment of the present invention, the logic gate device preferably comprises a reactivation device data supply output for outputting the target data to a reactivation device. According to a preferred embodiment of the present invention, the logic gate devicePreferably, a reactivation device data supply input for supplying the result data. According to a preferred embodiment of the present invention, the logic gate device preferably has a reactivation device control logic gate part. According to a preferred embodiment of the present invention, the logic gate device preferably has the reactivation device control logic gate part configured to convert original reactivation device control data into reactivation device control result data. According to a preferred embodiment of the present invention, a reactivation device control data output is provided for outputting the reactivation device control result data. According to a preferred embodiment of the present invention, a reactivation device control data input is provided for supplying the reactivation device control original data. According to a preferred embodimentof the present invention, at least one data verification logic gate part is provided. According to a preferred embodiment of the present invention, the at least one data verification logic gate part is configured to analyze digital result data with regard to malware. According to a preferred embodiment of the present invention, the data verification logic gate part compares representative information stored in a lookup table, in particular binary sequences or parts of the binary sequences of the malware, of malware with the binary sequence or parts of the binary sequence of the original data. According to a preferred embodiment of the present invention, the data verification logic gate part is configured to convert the result data into the original data in a first step and then effect the comparison with the representative information stored in the lookup table. According to a preferred embodiment of the presentAccording to the invention, a data verification logic gate sub-output or any data verification logic gate sub-output via which the original data generated from the result data can be output to an original data memory and / or the original data memory is physically separated from the storage device data memory and / or the reactivation device data memory, in particular in such a way that malware cannot reach the storage device data memory and / or the reactivation device data memory. According to a preferred embodiment of the present invention, the original data generated by the data verification logic gate sub-output are deleted after the comparison and preferably the memory area on which the data was provided is formatted. According to a preferred embodiment of the present invention, comparison data are generated depending on the comparison result, wherein the comparison data correspond to the data stored in the storage device.corresponding result data are assigned or the corresponding result data are supplemented by the comparison data. According to a preferred embodiment of the present invention, the comparison data comprises information on the version of the representation information and / or the comparison result. According to a preferred embodiment of the present invention, the data verification logic gate part compares binary sequences of malware result data held in a lookup table with the binary sequence of the result data. According to a preferred embodiment of the present invention, the binary sequences of the malware result data held in the lookup table are generated from malware original data according to the conversion of the original data into the result data. According to a preferred embodiment of the present invention, the logic gate device comprises a data verification device control logic gate part. According to a preferredAccording to a preferred embodiment of the present invention, the data verification device control logic gate part is configured to convert original data verification device control data into data verification device control result data. According to a preferred embodiment of the present invention, a data verification device control data output is provided for outputting the data verification device control result data. According to a preferred embodiment of the present invention, a data verification device control data input is provided for supplying the original data verification device control data. According to a preferred embodiment of the present invention, one or more FPGAs are provided. According to a preferred embodiment of the present invention, at least two or exactly two or at least three or exactly three or at least four or exactly four of the logic gates: passivation logic gate part,The retention device control logic gate part, the reactivation logic gate part, the reactivation device control logic gate part, the data verification logic gate part, and / or the data verification device control logic gate part are formed by an FPGA. According to a preferred embodiment of the present invention, at least two or exactly two or at least three or exactly three or at least four or exactly four of the logic gates: passivation logic gate part, retention device control logic gate part, the reactivation logic gate part, the reactivation device control logic gate part, the data verification logic gate part, and / or the data verification device control logic gate part are each formed by an FPGA. According to a preferred embodiment of the present invention, at least two or exactly two or at least three or exactly three or at least four or exactly four of the logic gates: passivation logic gate part, retention device controlLogic gate part, reactivation logic gate part, reactivation device control logic gate part, data verification logic gate part and / or data verification device control logic gate part are each formed by a plurality of FPGAs. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to establish, provide, determine, or generate different zero binary sequence representations and / or one binary sequence representations, in particular different combinations of zero binary sequence representations and / or one binary sequence representations, for the original data of a file. According to a further preferred embodiment of the present invention, the passivation logic gate part executes an algorithm for the predetermined establishment, generation, or determination of the zero binary sequence representations and / or the one binary sequence representations, or theThe passivation logic gate part executes a random algorithm for randomly determining or generating or determining the zero binary sequence representations and / or the one binary sequence representations, or one or more look-up tables with a plurality of predetermined zero-one binary sequence representation combinations are provided, and the passivation logic gate part is configured to select different zero-one binary sequence representation combinations, in particular to select them randomly, wherein the one look-up table or the plurality of look-up tables has at least 10, in particular at least 100 and preferably at least 1000 and particularly preferably more than 3000 and most preferably more than 5000 or 10000, different zero-one binary sequence representation combinations. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to, with respect to the original data of a fileto generate result data, wherein the result data can be generated with a plurality of mutually different zero binary sequence representations, wherein the mutually different zero binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to generate result data with respect to the original data of a file, wherein the result data can be generated with a plurality of mutually different one binary sequence representations, wherein the mutually different one binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to generate result data with respect to the original data of a file, wherein theResult data with a plurality of mutually different ones binary sequence representations can be generated, wherein the mutually different ones binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, and wherein the passivation logic gate part is configured to generate the result data with a plurality of mutually different zeros binary sequence representations, wherein the mutually different zeros binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, wherein the bit sequences of the result data for the zeros binary sequence representations and the ones binary sequence representations are different from one another. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to generate representative data for the result data, wherein the representative data indicates which zeros-Binary sequence representations and / or ones-binary sequence representations comprise the result data, in particular the respective concrete result data file. According to a further preferred embodiment of the present invention, the representative data indicate which zero binary sequence representations and / or which ones-binary sequence representations form the result data at which position in the result data. According to a further preferred embodiment of the present invention, the representative data identify a first ones-binary sequence representation with a first bit length in a first number for replacing the first number of ones of the original data, and the representative data identify a second ones-binary sequence representation with a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of ones of the original data comprises more than two consecutive ones or more than 10consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, and wherein the second number of ones of the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, wherein the first number and the second number are different from one another or wherein the first number and the second number are the same. According to a further preferred embodiment of the present invention, the representative data identifies a first zero binary sequence representation with a first bit length in a first number for replacing the first number of zeros of the original data and the representative data identifies a second zero binary sequence representation with a second bit length in a second number for replacing the secondNumber of ones in the original data, wherein the first number of zeros in the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros in the original data or preferably up to 10,000 consecutive zeros, and wherein the second number of zeros in the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros in the original data or preferably up to 10,000 consecutive zeros, wherein the first number and the second number are different from one another or wherein the first number and the second number are the same. According to a further preferred embodiment of the present invention, the number of different zero binary sequence representations and the number of different one binary sequence representations per result data, in particular per result data set or result data file,identical or different. According to a further preferred embodiment of the present invention, the representative data can be generated as part of the result data. According to a further preferred embodiment of the present invention, the representative data can be generated as a separate data set associated with the result data. According to a further preferred embodiment of the present invention, the reactivation device, in particular one or at least one logic gate, in particular an FPGA or ASIC, is configured to effect the conversion of the result data into the target data (22) depending on the representative data. Additionally or alternatively, the present invention can also relate to a method for data backup and preferably for data provision. The method preferably comprises at least the step of: converting digital source data into digital result data by means of a passivation device, wherein the passivation deviceat least one passivation logic gate, and wherein the at least one passivation logic gate is configured to convert the digital source data into the digital result data and to generate the result data, wherein the passivation device has a passivation device input interface for supplying the source data to the at least one passivation logic gate, and wherein the passivation device has a passivation device output interface for outputting the result data generated by the at least one passivation logic gate, wherein the digital source data is defined by a first binary sequence, wherein the digital result data is defined by a second binary sequence, wherein the first binary sequence and the second binary sequence are different from one another. Additionally or alternatively, the method preferably also comprises the step of converting the result data into target data by means of aReactivation device, wherein the reactivation device has a reactivation device input interface for supplying the result data to the reactivation device and preferably a reactivation device output interface for outputting the target data, wherein the target data preferably correspond to the original data by at least 90% or at least 95% or at least 99% or at least 99.9% or exactly 100%. The passivation logic gate is configured according to a preferred embodiment of the present invention to generate zero binary sequence representations for zeros of the first binary sequence of the digital original data, and wherein the passivation logic gate is configured to generate one binary sequence representations for ones of the first binary sequence of the digital original data. The zero binary sequence representation has according to a preferred embodiment of the present invention at least two bits and preferablymore than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits. According to a preferred embodiment of the present invention, the ones binary sequence representation has at least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits. According to a preferred embodiment of the present invention, the passivation logic gate is configured to specify or provide or determine or generate different zero binary sequence representations and / or ones binary sequence representations for different source data, in particular different files, in particular source data to be processed one after the other. To produceAccording to a preferred embodiment of the present invention, the passivation logic gate is configured to define, provide, determine, or generate different zero binary sequence representations and / or one binary sequence representations for the source data of a file, in particular the first binary sequence. According to a preferred embodiment of the present invention, the passivation logic gate executes an algorithm for the predetermined definition, generation, or determination of the zero binary sequence representations and / or the one binary sequence representations. Additionally or alternatively, the passivation logic gate executes a random algorithm for the random definition, generation, or determination of the zero binary sequence representations and / or the one binary sequence representations. Additionally or alternatively, a look-up table or multiple look-up tables with a plurality of defined zeros and onesBinary sequence representation combinations are provided and the passivation logic gate is preferably configured to select, in particular randomly select, different zeros-ones binary sequence representation combinations, wherein the one look-up table or the plurality of look-up tables has at least 10, in particular at least 100 and preferably at least 1000 and particularly preferably more than 3000 and most preferably more than 5000 or 10000, different zeros-ones binary sequence representation combinations. According to a preferred embodiment of the present invention, the one look-up table or the plurality of look-up tables comprise zero-one binary sequence representation combinations, wherein the zero-one binary sequence representation combinations comprise zero bit representations and one bit representations, wherein at least individual zero bit representations of the zero-one binary sequence representation combinations each comprise a first number of bits,and wherein at least individual ones-bit representations of the zeros-ones binary sequence representation combinations each have a second number of bits, wherein at least for individual zeros-ones binary sequence representation combinations, the first number of bits and the second number of bits are the same and / or wherein at least for individual zeros-ones binary sequence representation combinations, the first number of bits and the second number of bits are different. The look-up table or the look-up tables are / are provided or stored or deposited in a memory device of the passivation device according to a preferred embodiment of the present invention. The passivation logic gate is configured according to a preferred embodiment of the present invention to generate result data with respect to the source data of a file, wherein the result data are generated with a plurality of mutually different zeros binary sequence representations, wherein thedifferent zero binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length. The passivation logic gate is configured according to a preferred embodiment of the present invention to generate result data with respect to the original data of a file, wherein the result data is generated with a plurality of different one binary sequence representations, wherein the different one binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length. The passivation logic gate is configured according to a preferred embodiment of the present invention to generate result data with respect to the original data of a file, wherein the result data is generated with a plurality of different one binary sequence representations, wherein the different one binary sequence representationshave different length bit sequences and / or different bit sequences of the same length, and wherein the passivation logic gate is configured to generate the result data with a plurality of mutually different zero binary sequence representations, wherein the mutually different zero binary sequence representations have different length bit sequences and / or different bit sequences of the same length, wherein the bit sequences of the result data for the zero binary sequence representations and the one binary sequence representations are different from each other. The passivation logic gate is configured according to a preferred embodiment of the present invention to generate representative data for the result data or with respect to the result data, wherein the representative data indicates which zero binary sequence representations and / or one binary sequence representations the result data, in particular the respective concrete result data file, has. TheAccording to a preferred embodiment of the present invention, representative data indicate which zero binary sequence representations and / or which one binary sequence representations form the result data at which position in the result data. According to a preferred embodiment of the present invention, the representative data identify a first one binary sequence representation with a first bit length in a first number for replacing the first number of ones in the original data, and the representative data identify a second one binary sequence representation with a second bit length in a second number for replacing the second number of ones in the original data, wherein the first number of ones in the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones in the original data or preferably up to 10,000 consecutive ones, and wherein the secondNumber of ones of the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, wherein the first number and the second number are different from each other or wherein the first number and the second number are the same. According to a preferred embodiment of the present invention, the representative data identify a first zero binary sequence representation with a first bit length in a first number for replacing the first number of zeros of the original data and the representative data identify a second zero binary sequence representation with a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of zeros of the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than100 consecutive zeros of the original data or preferably up to 10,000 consecutive zeros, and wherein the second number of zeros of the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data or preferably up to 10,000 consecutive zeros, wherein the first number and the second number are different from one another or wherein the first number and the second number are the same. According to a further preferred embodiment of the present invention, the passivation logic gate is configured to divide the first binary sequence into original data bit sequences, wherein the original data bit sequences have a plurality of bits, wherein the plurality of bits consist of one "0" bit or a plurality of "0" bits and one "1" bit or a plurality of "1" bits or of "0" bits or of "1" bits, and wherein the passivation logic gate is configured tonumber of bits of each original data bit sequence in the representative data, and wherein the passivation logic gate is configured to store, in particular to generate or select, a bit representation combination in the representative data for each original data bit sequence, wherein each bit representation combination has a zero binary sequence representation or a link with a zero binary sequence representation for all "0" bits of an original data bit sequence, and wherein each bit representation combination has a one binary sequence representation or a link with a one binary sequence representation for all "1" bits of the same original data bit sequence, or wherein each bit representation combination has a zero-one binary sequence representation combination or a link with a zero-one binary sequence representation combination for all "0" bits and "1" bits of an original data bit sequence. The passivation logic gate is designed according to aAnother preferred embodiment of the present invention is configured to divide the first n bits of the first binary sequence into original data bit sequences whose average number of bits is less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the first n bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than 500 bits and most preferably less than 200 bits, and / or the passivation logic gate is configured to divide the last m bits of the first binary sequence into original data bit sequences whose average number of bits is less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the last m bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than 500 bits and most preferably less than 200 bits. The passivation logic gateAccording to a further preferred embodiment of the present invention, the passivation logic gate is configured to divide the first n bits of the first binary sequence into original data bit sequences whose number of bits is between 2 bits and 50 bits, in particular between 4 bits and 20 bits and preferably between 5 bits and 15 bits, and / or the passivation logic gate is configured to divide the last m bits of the first binary sequence into original data bit sequences whose number of bits is between 2 bits and 50 bits, in particular between 4 bits and 20 bits and preferably between 5 bits and 15 bits. According to a further preferred embodiment of the present invention, the passivation logic gate is configured to divide the bits between the first n bits, in particular 100 bits, of the first binary sequence and the last m bits, in particular 100 bits, of the first bit sequence into original data bit sequences whose average number of bits is greater than 20 bits, in particular greater thanthan 50 bits or greater than 100 bits. The number of different zero binary sequence representations and the number of different one binary sequence representations per result data, in particular per result data record or result data file, is the same or different according to a further preferred embodiment of the present invention. The representative data is generated as part of the result data according to a further preferred embodiment of the present invention. The representative data is generated as a separate data record associated with the result data according to a further preferred embodiment of the present invention. An analysis unit, in particular for determining or detecting at least one malware signature or malware signature data, is provided, wherein the analysis unit is configured to use result data, in particular also based on the representative data associated with or associated with the respective result data,Analysis bit representation data and / or a text representation with a text processing device, wherein the analysis bit representation data represent the first bit sequence in encrypted or coded form and wherein the analysis bit representation data can be analyzed with respect to a malicious code signature or malware signature contained in the first bit sequence or with respect to several malicious code signature data or malware signatures or malicious code signatures or malware signatures contained in the first bit sequence and / or wherein the text representation can be analyzed with respect to a malicious code signature or malware signature contained in the first bit sequence or with respect to several malicious code signature data or malware signatures or malicious code signatures or malware signatures contained in the first bit sequence. According to a further preferred embodiment of the present invention, the analysis unit has a processing device, in particular one orat least one logic gate device, such as an ASIC or an FPGA, and / or one or at least one CPU and / or one or at least one GPU, and a processing device 171, in particular a processing editor, in particular a color, grayscale, and / or character editor. The processing device can additionally or alternatively be designed as part of the passivation device or the reactivation device. According to a further preferred embodiment of the present invention, the analysis unit is configured to carry out an OCR analysis (“optical character recognition” analysis), wherein the OCR analysis can determine whether the translation of the malware signature in the information optically outputtable by means of the zero analysis bit representation and one analysis bit representation or the analyzable zero binary sequence representation and the analyzable one binary sequence representation, in particular character sequence and / orGray value sequence or gray tone sequence and / or color value sequence or color tone sequence. The analysis bit representation data with respect to the zero binary sequence representations of the result data, in particular of a result data file, according to a further preferred embodiment of the present invention, comprise a plurality of first bit blocks for at least or exactly one zero analysis bit representation of a standardization system, and wherein the analysis bit representation data with respect to the one binary sequence representations of the result data, in particular of a result data file, comprise a plurality of second bit blocks for at least or exactly one one analysis bit representation of the standardization system. According to a further preferred embodiment of the present invention, the standardization system comprises a plurality of different bit blocks, wherein each bit block is assigned a unique comparison parameter. The comparison parameter is according to a further preferred embodiment of the presentInvention selected from the following group of comparison parameters: symbols, colors, grayscale, tones and / or patterns. According to a further preferred embodiment of the present invention, the grayscale or color per bit block can be optically output by means of at least one pixel or more pixels, in particular 2, 3, 4, 5 or up to 10 or more than 10 or up to 200 pixels. According to a further preferred embodiment of the present invention, 4 or more than 4 or 8 or more than 8 or 16 or more than 16 or 32 or more than 32 or up to 32 or preferably 64 or more than 64 or up to 64 or particularly preferably 128 or more than 128 or up to 128 or most preferably 256 or more than 256 or up to 256 or more than 512 or up to 512 or more than 1024 or up to 1024 different bit blocks are provided. According to a further preferred embodiment of the present invention, the symbols are in the form of numbers and / or letters and / orCharacters, in particular numbers and / or letters and / or characters, in particular according to ASCII code. Additionally or alternatively, Chinese characters can be used. Additionally or alternatively, characters from different character systems, in particular sufficiently distinguishable ones, or characters developed specifically for the purpose of the present invention can be used. An assignment of bit blocks and symbols can, for example, look like this: According to a further preferred embodiment of the present invention, the colors are 128 different colors or more than 128 different colors, or preferably 256 different colors or more than 256 different colors, or 512 different colors or more than 512 different colors. An assignment of bit blocks and colors is according to a further preferred embodiment of the present invention: 0000000 Color value 1 0000001 Color value 2 ... 0111111 Color value 128. The gray levels are according to a further preferred embodiment of the present invention, 128 different gray levels or more than 128 different gray levels, or preferably 256 different gray levels or more than 256 different gray levels, or 512 different gray levels or more than 512 different gray levels. An assignment of bit blocks and gray levels is according to a further preferred embodiment of the present invention: 0000000Gray value 1 0000001 Gray value 2 ... 0111111 Gray value 128. According to a further preferred embodiment of the present invention, the data backup device and preferably the data backup and provision device comprises a data memory, wherein the analysis unit effects a data modification and / or data generation on the data memory and / or the deletion of data and / or the retrieval of data from the data memory. According to a further preferred embodiment of the present invention, the passivation device, in particular the passivation logic gate, is configured to randomly predetermine a zero analysis bit representation with respect to the zero binary sequence representations of the first binary sequence, and the passivation device, in particular the passivation logic gate, is configured to randomly predetermine a one analysis bit representation with respect to the one binary sequence representations of the first binary sequence.According to a further preferred embodiment of the present invention, the passivation device, in particular the passivation logic gate, is configured to generate the specification of the zero analysis bit representation and the one analysis bit representation as part of the result data and / or as part of the representation data and / or as part of the analysis bit representation data. According to a further preferred embodiment of the present invention, the analysis unit is configured to randomly specify, determine, or select at least one or exactly one zero analysis bit representation for generating the analysis bit representation data with respect to the zero binary sequence representations of the first binary sequence, and the analysis unit is configured to randomly specify, determine, or select at least one or exactly one one analysis bit representation for generating the analysis bit representation data with respect to the one binary sequence representations of the first binary sequence.According to a further preferred embodiment of the present invention, malware signature data is kept, in particular stored, in the data memory. The malware signature data can preferably be supplied to the memory by means of a terminal, in particular a keyboard or a camera or a drive, in particular a CD, DVD or Blu-ray or USB stick. The terminal is preferably permanently connected to the data backup and / or provision device. According to a further preferred embodiment of the present invention, the malware signature data is provided as malware signature reference data. According to a further preferred embodiment of the present invention, the analysis unit is configured to use the malware signature reference data to generate comparison data for comparison with the analysis bit representation data. According to a further preferred embodiment of the present invention, the analysis unit isInvention configured to generate comparison data for comparison with the analysis bit representation data and / or with the text representation of the bits of the digital original data based on the malware signature reference data or malware reference signature or based on the malware signature reference data or malware reference signature. According to a further preferred embodiment of the present invention, the comparison data is generated according to the at least one and preferably exactly one zero analysis bit representation and according to the at least one or preferably exactly one one analysis bit representation. According to a further preferred embodiment of the present invention, the malware signature data is provided as a malware signature comparison table, wherein the analysis unit is configured to select comparison data from the malware signature comparison table for comparison with the analysis bit representation data.According to a further preferred embodiment of the present invention, the reactivation device, in particular a logic gate, in particular an FPGA or ASIC, is configured to effect the conversion of the result data into the target data depending on the representative data or a part of the representative data or inverse representative data or a part of inverse representative data. Furthermore, the above-mentioned object can additionally or alternatively be achieved by a passivation system. The passivation system serves to convert digital source data into digital output data, wherein the digital output data represent the digital source data in a non-executable or passive state, and preferably to manipulate the digital output data in the non-executable state. The passivation system preferably comprises at least: a data processing device, wherein the data processing device has at least one data inputfor inputting the digital source data and a data output for outputting the digital output data, wherein the source data is defined by a first binary sequence, wherein the digital output data contains result data, wherein the result data represents the first binary sequence, wherein the data processing device has at least one passivation logic gate, in particular a Field Programmable Gate Array (FPGA) or Application Specific Integrated Circuit (ASIC) or Complex Programmable Logic Device (CPLD) or Simple Programmable Logic Device (SPLD), between the data input and the data output, wherein the passivation logic gate is configured to generate the digital output data, wherein the digital output data is defined by a second binary sequence, wherein the first binary sequence and the second binary sequence are different from one another. In the context of the present invention, non-executable means that a file can be modified in such a waythat malware represented in the binary sequence is modified in such a way that this malware cannot be activated (executed). According to a preferred embodiment of the present invention, the second binary sequence is longer than the first binary sequence, in particular the second binary sequence is at least by a factor of 1.2 or a factor of 1.6 or a factor of 2 or a factor of 4 or a factor of 8 longer than the first binary sequence and / or all contiguous bit sequences of the first binary sequence with a length of at least 0.001%, in particular at least 1% or preferably at least 10% or most preferably at least 20%, of the total length of the first binary sequence are different from all contiguous bit sequences of the second binary sequence with a length of at least 0.001%, in particular at least 1% or preferably at least 10% or most preferably at least 20%, of the total length of the first binary sequence and / or all contiguous bit sequences of the first binary sequence witha length of at least 32 bits, in particular at least 64 bits, at least 128 bits, at least 256 bits or at least 512 bits, are different from all contiguous bit sequences of the second binary sequence with a length of at least 32 bits, in particular at least 64, at least 128, at least 256 or at least 512 bits. According to a preferred embodiment of the present invention, the digital original data can be introduced as an original data file or as an original data stream via the data input and / or the digital output data can be output as a result data file or as an output data stream for generating a result data file via the data output. According to a preferred embodiment of the present invention, the result data file has the result data in the form of a preferably machine-readable character encoding. According to a preferred embodiment of the present invention, the character encoding is preferably a 2-bit character encoding or a3-bit character encoding or a 4-bit character encoding or a character encoding with more than 4 bits, in particular 7, 8 or 18 bits, in particular American Standard Code for Information Interchange (ASCII) or Indian Script Code for Information Interchange (ISCII) or Tamil Script Code for Information Interchange (TSCII). According to a preferred embodiment of the present invention, the result data of the result data file represent color values ​​and / or brightness values. According to a preferred embodiment of the present invention, a function system is provided, wherein the function system is coupled to the data input of the data processing device. According to a preferred embodiment of the present invention, a storage system is provided, wherein the storage system is coupled to the data output of the data processing device and wherein the storage system is for storing the result data file and / or for generating the result data file by means of theOutput data streams are configured. According to a preferred embodiment of the present invention, a data verification system is provided, wherein the storage system and the data verification system are connected to one another directly or indirectly via a bidirectional or unidirectional data line, in particular an optical fiber, wherein the bidirectional or unidirectional data line connects a data output of the storage system and a data input of the data verification system, wherein data can be conducted from the storage system to the data verification system via the bidirectional or unidirectional data line. According to a preferred embodiment of the present invention, the data verification system has a data verification logic gate, in particular a Field Programmable Gate Array (FPGA) or application-specific integrated circuit (ASIC) or software configurable processor (SCP) or complex programmable logic device (CPLD) or simple programmableLogic Device (SPLD), in particular a malware identification program or malware identification hardware, for analyzing the result data. According to a preferred embodiment of the present invention, the result data can be analyzed with regard to the bit sequences they represent. According to a preferred embodiment of the present invention, a data verification system is provided, wherein a data output of the memory system is connected to an input of a data verification logic gate, in particular a Field Programmable Gate Array (FPGA) or Application Specific Integrated Circuit (ASIC) or Complex Programmable Logic Device (CPLD) or Simple Programmable Logic Device (SPLD), and wherein an output of the logic gate is connected to an input of the data verification system, wherein result data from the data verification logic gate, which can be fed to the input of the data verification logic gate via the data output of the memory system,processable and fed to the input of the data verification system. According to a preferred embodiment of the present invention, a data output of the data verification system is connected to the logic gate via a data connection, wherein the result data fed from the logic gate to the data verification system via the data input of the data verification system can be fed back to the logic gate via the data connection. According to a preferred embodiment of the present invention, the logic gate is linked to a data verification system data memory, wherein the data verification system data memory has at least malware representation data. According to a preferred embodiment of the present invention, the malware representation data of a malware has a malware representation data binary sequence, wherein the malware representation data binary sequence is different from the binary sequence of the malware. According to a preferredIn an embodiment of the present invention, the malware representation data binary sequence is longer than the binary sequence of the malware, in particular the malware representation data binary sequence is at least by a factor of 1.2 or a factor of 1.6 or a factor of 2 or a factor of 4 or a factor of 8 longer than the binary sequence of the malware, and / or all contiguous bit sequences of the binary sequence of the malware with a length of at least 0.001%, in particular at least 1% or preferably at least 10% or most preferably at least 20%, of the total length of the binary sequence of the malware are different from all contiguous bit sequences of the malware representation data binary sequence with a length of at least 0.001%, in particular at least 1% or preferably at least 10% or most preferably at least 20%, of the total length of the binary sequence of the malware and / or all contiguous bit sequences of the binary sequence of the malware with a length of at least 32 bits,in particular at least 64, at least 128, at least 256 or at least 512 bits, are different from all contiguous bit sequences of the malware representation data binary sequence with a length of at least 32 bits, in particular at least 64, at least 128, at least 256 or at least 512 bits. According to a preferred embodiment of the present invention, the malware representation data in the data verification system data memory is updateable. According to a preferred embodiment of the present invention, the storage system and the data verification system are connected to one another directly or indirectly via a bidirectional or unidirectional data line, in particular an optical fiber, wherein the bidirectional or unidirectional data line connects a data output of the storage system and a data input of the data verification system, wherein data is transmitted from the storage system to theData verification system. According to a preferred embodiment of the present invention, the data verification system comprises a malware identification program or malware identification hardware, in particular a Field Programmable Gate Array (FPGA) or Application Specific Integrated Circuit (ASIC) or Software Configurable Processor (SCP) or Complex Programmable Logic Device (CPLD) or Simple Programmable Logic Device (SPLD), for analyzing the result data. According to a preferred embodiment of the present invention, the result data can be analyzed with regard to the bit sequences they represent. According to a preferred embodiment of the present invention, the data verification system comprises an update data input. According to a preferred embodiment of the present invention, the functional system or an Internet connection device comprises an update data output, wherein the update data output of theFunctional system or the Internet connection device and the update data input of the data verification system are connected to one another via an encryption and / or decryption logic gate, in particular a Field Programmable Gate Array (FPGA) or application-specific integrated circuit (ASIC) or Complex Programmable Logic Device (CPLD) or Simple Programmable Logic Device (SPLD), wherein the encryption and / or decryption logic gate is configured to decrypt update data supplied via the update data input. According to a preferred embodiment of the present invention, the encryption and / or decryption logic gate decrypts the update data depending on at least one defined parameter, in particular the time, the date and / or a code. According to a preferred embodiment of the present invention, the update input is functionally connected to an update data memory for storing theUpdate data is connected, wherein the update data memory and a digital output of the data verification system are separated by at least one logic gate. According to a further preferred embodiment of the device or the system according to the invention, a deactivation device is provided for deactivating the data backup and provision device, in particular the passivation device, and / or for deactivating data forwarding, in particular from a system on which the digital original data is stored and from which the original data can be supplied to the passivation device, to the data backup and provision device, wherein the deactivation device preferably, depending on status data of the digital original data and / or system status data of the system on which the digital original data is stored and from which the original data can be supplied to the passivation device,Data backup and provision device, in particular the passivation device, is deactivated. According to a further preferred embodiment, the deactivation of the data backup and provision device, in particular the passivation device, represents a physical disconnection of a data connection via which the original data can be supplied to the passivation device in a connected state, the setting of an inactive state, wherein in the inactive state the conversion of the digital original data into the digital result data is paused or terminated, or the interruption of a power supply to the passivation device or a physical disconnection of a data connection connected to the passivation device output interface, wherein in a connected state the digital result data can be output to another device, in particular the storage device data memory. The deactivation device is preferablyPart of the system on which the digital original data is stored and from which the original data can be supplied to the passivation device, and / or part of the data backup and / or provision device. The inactivation device is particularly preferably configured to analyze the system on which the digital original data is stored and from which the original data can be supplied to the passivation device with regard to encryption parameters. According to a further preferred embodiment, the inactivation device is configured as an intrusion protection system (IPS) or is connected to an intrusion protection system (IPS) via data and / or signal technology. IPS systems are described, for example, by the following Internet reference: https: / / www.informatik-aktuell.de / betrieb / sicherheit / ransomware-angriffe-erkennen-und-stoppen.html. According to a further preferred embodiment of the device according to the invention or theIn a system according to the invention, the passivation logic gate is configured to generate zero binary sequence representations for zeros of the first binary sequence of the digital original data, and wherein the passivation logic gate is configured to generate one binary sequence representations for ones of the first binary sequence of the digital original data. According to a further preferred embodiment of the present invention, the zero binary sequence representation has at least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits. According to a further preferred embodiment, the ones binary sequence representation has at least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7Bit or more than 7 bits or 8 bits or more than 8 bits. According to a further preferred embodiment, the passivation logic gate is configured to establish or provide or determine or generate different zero binary sequence representations and / or one binary sequence representations for different source data, in particular different files, in particular source data to be processed one after the other. According to a further preferred embodiment, the passivation logic gate is configured to establish or provide or determine or generate different zero binary sequence representations and / or one binary sequence representations for source data of a file. According to a further preferred embodiment of the present invention, the passivation logic gate is configured to implement an algorithm for the predetermined establishment or generation or determination of the zero binary sequence representations and / or theOnes binary sequence representations or the passivation logic gate is configured to execute a random algorithm for randomly determining or generating or determining the zeros binary sequence representations and / or the ones binary sequence representations or one or more look-up tables with a plurality of defined zeros-ones binary sequence representation combinations are provided and the passivation logic gate is configured to select different zeros-ones binary sequence representation combinations, in particular to select them randomly, wherein the one look-up table or the plurality of look-up tables has at least 10, in particular at least 100 and preferably at least 1000 and particularly preferably more than 3000 and most preferably more than 5000 or 10000, different zeros-ones binary sequence representation combinations. The one look-up table or the plurality of look-up tables have, according to a further preferredEmbodiment of the present invention comprises zero-one binary sequence representation combinations, wherein the zero-one binary sequence representation combinations comprise zero bit representations and one bit representations, wherein at least individual zero bit representations of the zero-one binary sequence representation combinations each comprise a first number of bits, and wherein at least individual one bit representations of the zero-one binary sequence representation combinations each comprise a second number of bits, wherein at least for individual zero-one binary sequence representation combinations the first number of bits and the second number of bits are the same and / or wherein at least for individual zero-one binary sequence representation combinations the first number of bits and the second number of bits are different. The look-up table or the look-up tables is / are according to a further preferred embodiment of the present invention in aThe passivation logic gate is configured according to a further preferred embodiment of the present invention to generate result data with respect to the original data of a file, wherein the result data can be generated with a plurality of mutually different zero binary sequence representations, wherein the mutually different zero binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length. The passivation logic gate is configured according to a further preferred embodiment of the present invention to generate result data with respect to the original data of a file, wherein the result data can be generated with a plurality of mutually different one binary sequence representations, wherein the mutually different one binary sequence representations have bit sequences of different lengths and / ordifferent bit sequences of the same length. According to a further preferred embodiment of the present invention, the passivation logic gate is configured to generate result data with respect to the original data of a file, wherein the result data can be generated with a plurality of mutually different one-binary sequence representations, wherein the mutually different one-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, and wherein the passivation logic gate is configured to generate the result data with a plurality of mutually different zero-binary sequence representations, wherein the mutually different zero-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, wherein the bit sequences of the result data for the zero-binary sequence representations and the one-binary sequence representations areare different. The passivation logic gate is configured according to a further preferred embodiment of the present invention to generate representative data for the result data, wherein the representative data indicates which zero binary sequence representations and / or one binary sequence representations the result data, in particular the respective result data file, has. According to a further preferred embodiment of the present invention, the representative data indicates which zero binary sequence representations and / or which one binary sequence representations form the result data at which position in the result data. According to a further preferred embodiment of the present invention, the representative data identify a first one binary sequence representation with a first bit length in a first number for replacing the first number of ones of the original data, and the representative data identify a second one-Identify binary sequence representations with a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of ones of the original data preferably comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, and wherein the second number of ones of the original data preferably comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, wherein the first number and the second number are different from one another or wherein the first number and the second number are the same. According to a further preferred embodiment of the present invention, the representative data identify a firstZero binary sequence representations with a first bit length in a first number for replacing the first number of zeros of the original data and the representative data preferably identify a second zero binary sequence representation with a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of zeros of the original data preferably comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data or preferably up to 10,000 consecutive zeros and wherein the second number of zeros of the original data preferably comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data or preferably up to 10,000 consecutive zeros, wherein the first number and the second number are different from each other or whereinthe first number and the second number are equal. The number of different zero binary sequence representations and the number of different one binary sequence representations per result data, in particular per result data set or result data file, are the same or different according to a further preferred embodiment of the present invention. The passivation logic gate is configured according to a further preferred embodiment of the present invention to divide the first binary sequence into original data bit sequences, wherein the original data bit sequences have a plurality of bits, wherein the plurality of bits consists of one "0" bit or a plurality of "0" bits and of one "1" bit or a plurality of "1" bits or of "0" bits or of "1" bits, and wherein the passivation logic gate is preferably configured to store the number of bits of each original data bit sequence in the representative data, and wherein the passivation logic gate is preferably configured forto store, in particular to generate or select, a bit representation combination in the representative data for each source data bit sequence. Each bit representation combination preferably has a zero binary sequence representation or a link with a zero binary sequence representation for all "0" bits of an source data bit sequence, and wherein each bit representation combination preferably has a one binary sequence representation or a link with a one binary sequence representation for all "1" bits of the same source data bit sequence. Alternatively, each bit representation combination has a zero-one binary sequence representation combination or a link with a zero-one binary sequence representation combination for all "0" and "1" bits of an source data bit sequence. The passivation logic gate is configured according to a further preferred embodiment of the present invention to convert the first n bits of the first binary sequence intoTo divide original data bit sequences whose average number of bits is preferably less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the first n bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than 500 bits and most preferably less than 200 bits. Additionally or alternatively, the passivation logic gate is configured to divide the last m bits of the first binary sequence into original data bit sequences whose average number of bits is preferably less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the last m bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than 500 bits and most preferably less than 200 bits. The passivation logic gate is according to another preferred embodiment of the present inventionconfigured to divide the first n bits of the first binary sequence into original data bit sequences whose number of bits lies between 2 bits and 50 bits, in particular between 4 bits and 20 bits and preferably between 5 bits and 15 bits, and / or the passivation logic gate is configured to divide the last m bits of the first binary sequence into original data bit sequences whose number of bits lies between 2 bits and 50 bits, in particular between 4 bits and 20 bits and preferably between 5 bits and 15 bits. According to a further preferred embodiment of the present invention, the passivation logic gate is configured to divide the bits between the first n bits, in particular 100 bits, of the first binary sequence and the last m bits, in particular 100 bits, of the first bit sequence into original data bit sequences whose average number of bits is greater than 20 bits, in particular greater than 50 bits or greater than 100 bits. The representative data are according to aAccording to a further preferred embodiment of the present invention, the representative data can be generated as part of the result data. According to a further preferred embodiment of the present invention, the representative data can be generated as a separate data set associated with the result data. According to a further preferred embodiment of the present invention, an analysis unit is provided for determining malware signature data. According to a further preferred embodiment of the present invention, the analysis unit is configured to generate analysis bit representation data based on result data, in particular also based on the representative data associated with or associated with the respective result data. According to a further preferred embodiment of the present invention, the analysis bit representation data represents the first bit sequence in encrypted form. According to a further preferred embodiment of the present invention, the analysis bit representation data iscan be analyzed with respect to a malicious code signature contained in the first bit sequence or with respect to a plurality of malware signature data contained in the first bit sequence. The analysis bit representation data with respect to the zero binary sequence representations of the result data, in particular of a result data file, according to a further preferred embodiment of the present invention, comprises a plurality of first bit blocks for at least or exactly one zero analysis bit representation of a standardization system. The analysis bit representation data with respect to the one binary sequence representations of the result data, in particular of a result data file, according to a further preferred embodiment of the present invention, comprises a plurality of second bit blocks for at least or exactly one one analysis bit representation of the standardization system. The standardization system according to a further preferred embodiment of the present invention has a plurality of different bit blocks, wherein preferablyEach bit block is assigned a unique comparison parameter. According to a further preferred embodiment of the present invention, the comparison parameters are symbols, colors, grayscale, tones, and / or patterns. According to a further preferred embodiment of the present invention, the grayscale or colors per bit block can be optically output by means of at least one pixel or several pixels, in particular 2, 3, 4, 5, or up to 10 or more than 10 or up to 200 pixels. According to a further preferred embodiment of the present invention, 4 or more than 4 or 8 or more than 8 or 16 or more than 16 or 32 or more than 32 or up to 32 or preferably 64 or more than 64 or up to 64 or particularly preferably 128 or more than 128 or up to 128 or most preferably 256 or more than 256 or up to 256 different bit blocks are provided. According to a further preferred embodiment of the present invention, the symbols are provided as numbers.and / or letters and / or characters, especially numbers and / or letters and / or characters according to ASCII code. An assignment of bit blocks and symbols is:

[0002] According to a further preferred embodiment of the present invention, the colors are 128 different colors or more than 128 different colors or preferably 256 different colors or more than 256 different colors or 512 different colors or more than 512 different colors. An assignment of bit blocks and colors is according to a further preferred embodiment of the present invention: 0000000 color value 1 0000001 color value 2 ... 0111111 color value 128. The gray levels are according to a further preferred embodiment of the present invention 128 different gray levels or more than 128 different gray levels or preferably 256 different gray levels or more than 256 different gray levels or 512 different gray levels or more than 512 different gray levels. An assignment of bit blocks and gray levels is according to a further preferred embodiment of the present invention: 0000000 gray value1 0000001 Gray value 2 ... 0111111 Gray value 128. According to a further preferred embodiment of the present invention, the data backup and provision device comprises a data memory, wherein the analysis unit can effect a data modification and / or data generation on the data memory and / or the deletion of data and / or the retrieval of data from the data memory. According to a further preferred embodiment of the present invention, the passivation device, in particular the passivation logic gate, is configured to randomly predetermine a zero analysis bit representation with respect to the zero binary sequence representations of the first binary sequence, and the passivation device, in particular the passivation logic gate, is configured to randomly predetermine a one analysis bit representation with respect to the one binary sequence representations of the first binary sequence. The passivation device, in particular the passivation logic gate, isAccording to a further preferred embodiment of the present invention, the analysis unit is configured to generate the specification of the zero analysis bit representation and the one analysis bit representation as part of the result data and / or as part of the representation data and / or as part of the analysis bit representation data. According to a further preferred embodiment of the present invention, the analysis unit is configured to randomly specify, determine, or select at least one or exactly one zero analysis bit representation for generating the analysis bit representation data with respect to the zero binary sequence representations of the first binary sequence, and the analysis unit is configured to randomly specify, determine, or select at least one or exactly one one analysis bit representation for generating the analysis bit representation data with respect to the one binary sequence representations of the first binary sequence. According to a further preferred embodiment, the data memory is / areAccording to a further preferred embodiment of the present invention, one or more malware signature data can be retained, in particular stored. According to a further preferred embodiment of the present invention, the malware signature data can be provided as malware signature reference data. According to a further preferred embodiment of the present invention, the analysis unit is configured to use the malware signature reference data to generate comparison data for comparison with the analysis bit representation data. According to a further preferred embodiment of the present invention, the comparison data can be generated according to the at least one, and preferably exactly one, zero analysis bit representation and according to the at least one, or preferably exactly one, one analysis bit representation. According to a further preferred embodiment of the present invention, the malware signature data can be provided as a malware signature comparison table.wherein the analysis unit is configured to select comparison data from the malware signature comparison table for comparison with the analysis bit representation data. The reactivation device, in particular a logic gate, in particular an FPGA or ASIC, is configured according to a further preferred embodiment of the present invention to effect the conversion of the result data into the target data depending on the representation data. The passivation logic gate part is configured according to a further preferred embodiment of the present invention to generate zero binary sequence representations for zeros of the first binary sequence of the digital original data, and wherein the passivation logic gate part is preferably configured to generate one binary sequence representations for ones of the first binary sequence of the digital original data. The zero binary sequence representations comprise, according to a further preferred embodiment of the present inventionat least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits. According to a further preferred embodiment of the present invention, the one-binary sequence representation has at least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to define or provide different zero-binary sequence representations and / or one-binary sequence representations for different source data, in particular different files, in particular source data to be processed one after the other, orto determine or generate. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to define or provide or determine or generate different zero binary sequence representations and / or one binary sequence representations for source data of a file. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to execute an algorithm for predetermined definition or generation or determination of the zero binary sequence representations and / or the one binary sequence representations, or the passivation logic gate part is configured to execute a random algorithm for random definition or generation or determination of the zero binary sequence representations and / or the one binary sequence representations, or one or more look-up tables with a plurality of definedZero-one binary sequence representation combinations are provided and the passivation logic gate part is configured to select different zero-one binary sequence representation combinations, in particular to select them randomly, wherein the one look-up table or the plurality of look-up tables has at least 10, in particular at least 100 and preferably at least 1000 and particularly preferably more than 3000 and most preferably more than 5000 or 10000, different zero-one binary sequence representation combinations. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to generate result data with respect to the source data of a file, wherein the result data can preferably be generated with a plurality of mutually different zero binary sequence representations, wherein the mutually different zero binary sequence representations have bit sequences of different lengths and / or differentHave bit sequences of equal length. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to generate result data with respect to the original data of a file, wherein the result data can preferably be generated with a plurality of mutually different one-binary sequence representations, wherein the mutually different one-binary sequence representations have bit sequences of different lengths and / or different bit sequences of equal length. According to a further preferred embodiment of the present invention, the passivation logic gate part is configured to generate result data with respect to the original data of a file, wherein the result data can preferably be generated with a plurality of mutually different one-binary sequence representations, wherein the mutually different one-binary sequence representations have bit sequences of different lengths and / or different bit sequences of equal length.and wherein the passivation logic gate part is preferably configured to generate the result data with a plurality of mutually different zero binary sequence representations, wherein the mutually different zero binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, wherein the bit sequences of the result data for the zero binary sequence representations and the one binary sequence representations are different from one another. The passivation logic gate part is configured according to a further preferred embodiment of the present invention to generate representative data for the result data, wherein the representative data indicates which zero binary sequence representations and / or one binary sequence representations the result data, in particular the respective result data file, has. According to a further preferred embodiment of the present invention, the representative data indicates whichZero binary sequence representations and / or which one binary sequence representations form the result data at which position in the result data. According to a further preferred embodiment of the present invention, the representative data identify a first one binary sequence representation with a first bit length in a first number for replacing the first number of ones in the original data, and the representative data preferably identify a second one binary sequence representation with a second bit length in a second number for replacing the second number of ones in the original data, wherein the first number of ones in the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones in the original data or preferably up to 10,000 consecutive ones, and wherein the second number of ones in the original data preferably comprises more than two consecutive onesor more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, wherein the first number and the second number are different from each other or wherein the first number and the second number are the same. According to a further preferred embodiment of the present invention, the representative data identify a first zero binary sequence representation with a first bit length in a first number for replacing the first number of zeros of the original data and the representative data preferably identify a second zero binary sequence representation with a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of zeros of the original data preferably comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original dataor preferably comprises up to 10,000 consecutive zeros, and wherein the second number of zeros of the original data preferably comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data, or preferably up to 10,000 consecutive zeros, wherein the first number and the second number are different from one another or wherein the first number and the second number are the same. The number of different zero binary sequence representations and the number of different one binary sequence representations per result data, in particular per result data record or result data file, is the same or different according to a further preferred embodiment of the present invention. The representative data can be generated as part of the result data according to a further preferred embodiment of the present invention. The representative data are according to a further preferredEmbodiment of the present invention can be generated as a separate data set associated with the result data. The reactivation device, in particular a logic gate, in particular an FPGA or ASIC, is configured according to a further preferred embodiment of the present invention to effect the conversion of the result data into the target data depending on the representative data. Features disclosed herein with regard to systems or devices are also deemed to be disclosed for the methods disclosed herein and vice versa, insofar as this is technically reasonable for a person skilled in the art. The associated figures show purely exemplary possible embodiments of the present invention, whereby the invention is not limited to these embodiments. Therein: Fig. 1a shows a first purely schematic example of a data backup and / or provision device according to the invention, whereby the illustration merely represents an example of the path of the data to be backed up.and / or data to be processed, Fig.1b shows a second purely schematic example of a data backup and / or provision device according to the invention, wherein the illustration is intended to illustrate only one example of the path of the data to be backed up and / or processed, Fig.1c shows a third purely schematic example of a data backup and / or provision device according to the invention, wherein the illustration is intended to illustrate only one example of the path of the data to be backed up and / or processed, Fig.2a shows a fourth purely schematic example of a data backup and / or provision device according to the invention, wherein the illustration is intended to illustrate only one example of the path of the data to be backed up and / or processed, Fig.2b shows a fifth purely schematic example of a data backup and / or provision device according to the invention, wherein the illustration is intended to illustrate only one example of the path of theto be secured and / or processed, Fig. 2c shows a sixth purely schematic example of a data backup and / or provision device according to the invention, wherein the illustration is intended to illustrate only one example of the path of the data to be secured and / or processed; Fig. 3 shows a seventh purely schematic example of a data backup and / or provision device according to the invention, wherein this example basically corresponds to the structure according to Fig. 1c and also exemplifies communication channels for controlling one or more of the existing devices; Fig. 4 shows an eighth purely schematic example of a data backup and / or provision device according to the invention, wherein this example basically corresponds to the structure according to Fig. 2a and also exemplifies communication channels for controlling one or more of the existing devices; Fig. 5 shows a ninth purely schematic example of adata backup and / or provision device according to the invention and also shows, by way of example, communication channels for controlling one or more of the existing devices; Fig. 6 shows a tenth, purely schematic example of a data backup and / or provision device according to the invention, this example basically corresponding to the structure according to Fig. 2b and also shows, by way of example, communication channels for controlling one or more of the existing devices, wherein individual communication channels or multiple communication channels can be implemented by means of an analog interface; Fig. 7 shows an eleventh, purely schematic example of a data backup and / or provision device according to the invention and also shows, by way of example, communication channels for controlling one or more of the existing devices, wherein individual communication channels or multiple communication channels can be implemented by means of an analog interface;Fig. 8 shows a twelfth purely schematic example of a data backup and / or provision device according to the invention and also exemplary communication channels for controlling individual or multiple devices; Fig. 9 shows a thirteenth purely schematic example of a data backup and / or provision device according to the invention and also exemplary communication channels for controlling individual or multiple devices, wherein individual communication channels or multiple communication channels can be implemented by means of an analog interface; Fig. 10 shows a fourteenth purely schematic example of a data backup and / or provision device according to the invention; Fig. 11a shows schematically an example of a reactivation device as can be implemented within the scope of the present invention, and Fig. 11b shows a further example of a reactivation device as can be implemented within the scope of the present invention.can be; Fig. 12 shows an example of a passivation device, wherein the passivation device according to this embodiment can be designed with a transmit logic gate and a receive logic gate; Fig. 13a-c show, purely by way of example, an example of data handling with regard to the passivation device shown in Fig. 12; Fig. 14 shows an exemplary schematic representation of the overall system; Fig. 15 shows a further exemplary variant of the representation of the overall system; Fig. 16 shows an exemplary schematic representation of the usage sequence of the overall system; Fig. 17 shows an exemplary schematic representation of the memory occupancy by the original data, the memory occupancy in the case of “Stage 1: STORAGE” and the memory occupancy in the case of “Stage 2: ANALYSIS / RESTORATION”; Fig. 18 shows an exemplary schematic representation of the conversion of the original data into data encrypted according to “Stage 1: STORAGE”; Fig.19 exemplary schematic representation of look-up tables, where each row of theLook-up tables have different combinations of zeros and ones as replacements for the zeros and ones of the original data; Fig.20 exemplary schematic representation of the generation of the “Stage 2: ANALYSIS / RESTORATION” encryption; Fig.21 alternative exemplary schematic representation of the generation of the “Stage 2: ANALYSIS / RESTORATION” encryption; Fig.22 exemplary schematic representation of the processing of malware signatures and exemplary schematic representation of the file analysis; Fig.23 exemplary schematic representation of the file recovery; Fig.24 exemplary generation of an encrypted file, wherein an analyzable zeros binary sequence representation and an analyzable ones binary sequence representation are used; and Fig.25a Example of 95 different bit representations and Fig.25b Example of 95 look-up tables with 94 pairs each consisting of a first bit block 196 and a second bit block 197. Fig.1ashows a purely schematic view of a work system 100, wherein the work system 100 in all embodiments of the present invention can be a computer unit, in particular a PC or a laptop or a mobile phone or a control device of a machine or a server. Alternatively, a control device 300 can be formed between the data backup and / or provision device 1 according to the invention and a work system 100, wherein in this case the control device 300 communicates with the work system 100 on the one hand and with the data backup and / or provision device 1 on the other hand. The control device 300 can be part of the data backup and / or provision device 1 in all embodiments of the present invention, although this is not absolutely necessary. The data backup and / or provision device 1 can, for example, also be directly connected to the work system 100 in all embodiments of the present invention.be coupled and / or communicate. The reference system 4 identifies digital source data that is to be protected, in particular, from encryption. The passivation device 2, which in all embodiments of the present invention can preferably be designed as one or more logic gate devices, in particular FPGA or ASIC or CPLD or SPLD, receives the digital source data 4 and converts it into digital result data 6 using a passivation logic gate 8. Due to the physical design of the passivation logic gate, the source data or any data supplied to the passivation logic gate 8 is processed in the same way. The passivation logic gate 8 converts the digital source data into non-executable digital result data in all embodiments of the present invention. Preferably, for example, each binary value ("0" and "1") is written as text ("0" and "1") in a file, whereby thedigital result data 6 has a textual representation of the binary sequence of the original data. However, the textual representation is not executable, and the binary sequence of the textual representation can essentially be formed from the binary sequences "00110000" and "00110001" of the ASCII codes for the numbers "0" and "1". Alternatively, color values, gray values, temperature values, or other characters can be used to represent the binary values ​​("0" and "1"). Reference numeral 80 denotes a reactivation device. The reactivation device 80 preferably serves to convert the digital result data 6 into a data form corresponding to the digital original data 4. The reactivation device 80 preferably has a CPU and / or GPU or a logic gate for converting the digital result data into the digital original data 4. Furthermore, the CPU and / or GPU or a logic gate can be designed to perform a malware analysis, whereinthe digital result data or the regenerated digital original data are analyzed for malware. The conversion of the digital result data and / or the malware analysis preferably takes place in a sandbox generated and / or executed by the CPU and / or GPU. Preferably, a malware analysis is performed first with respect to the digital result data and, in a further step, a malware analysis is performed with respect to the regenerated original data. However, it is also possible for only one of the two or no malware analysis to be carried out or provided. Particularly preferably, a sandbox can be generated for each unit of digital result data or for each result data file. Furthermore, a memory allocation in the sense of a DMZ (demilitarized zone) can be provided for the respective sandbox. Fig. 1b alternatively shows that the passivation device 2 and the reactivation device 80 can alternatively be provided in one device.can. Fig. 1c shows that, in contrast to the embodiment according to Fig. 1a, a holding device 28 can be provided between the passivation device 2 and the reactivation device 80. The digital result data 6 generated by the passivation device 2 can then be stored in a data memory of the holding device 28 and forwarded to the reactivation device 80 or mirrored to the reactivation device 80. Fig. 2a shows, in contrast to the embodiment according to Fig. 1c, that the passivation device 2 can be part of the holding device 28. Fig. 2b shows that the holding device according to Fig. 1c can also be configured for malware analysis. Preferably, the holding device has a CPU and / or GPU or a logic gate for malware analysis. In the malware analysis, binary components, in particular binary sequences, of the digital result data are preferably combined with binary components, in particular binary sequences, ofMalware. Preferably, the comparison binary sequences of the malware are generated analogously to the translation of the digital source data 4 into the digital result data 6. This is advantageous since the binary sequences of the malware can be very long, i.e., more than 16 bits and preferably more than 32 bits or more than 64 bits or more than 128 bits, and yet the comparison sequence itself - since it is not executable - cannot cause any damage. Fig. 2c shows a combination of embodiments 2a and 2b. The storage device 28 thus has the passivation device 2 and a malware analysis device, in particular CPU and / or GPU or a logic gate, in particular a data verification logic gate 69. Embodiments 2b and 2c are advantageous since the digital result data 6 stored in a data memory of the storage device 28 can be updated continuously or according to defined criteria or after each update ofMalware identification data can be analyzed for malware without the digital result data having to be converted back into the original data. Furthermore, this represents a high availability of all digital original data stored in the form of digital result data, especially with large data sets. Furthermore, the logic gate-based comparison of binary sequences, in particular by means of FPGA or ASIC, can be carried out very quickly and is resource-efficient. Fig. 3 schematically shows that the update device 54 of the reactivation device 80 is updateable via a network, in particular the Internet, or the work system 100 or the control device 300. Preferably, an update of a lookup table of a logic gate, in particular an FPGA or ASIC, is carried out, which prevents the update data from contaminating the remaining data memories in the case of contaminated update data. Furthermore, Fig. 3 shows by way of example that control data forControl of the holding device 28 in the form of original holding device control data 25, in particular from the work system 100 or the control device 300, can be supplied to a holding device control logic gate part 37, in particular at least one FPGA or ASIC, and is converted by the holding device control logic gate part 37 into holding device control result data 26. Preferably, the holding device control logic gate part 37 only outputs a defined number of commands or only defined commands. This is advantageous because the supplied original holding device control data 25 can, as an effect, only trigger one of the defined commands. It is also possible for the holding device control logic gate part 37 to only output the commands in the form of holding device control result data 26 or for the commands to only be processed if the commands correspond to a defined sequence of commands. This isadvantageous because, for example, attacks that represent a high number of repetitions of the same command or the same command sequence can be blocked or filtered out. In the event that commands deviating from the defined sequence of commands occur, for example, an alarm signal can be issued or the device 1 can be shut down, etc. Additionally or alternatively, for controlling the reactivation device 80, original reactivation device control data 77, in particular from the work system 100 or the control device 300, can be supplied to a reactivation device control logic gate part 78, in particular at least one FPGA or ASIC. The reactivation device control logic gate part 78 is configured to generate reactivation device control result data 79 based on the original reactivation device control data 77. Preferably, the reactivation device control logic gate part 78 only outputs adefined number of commands or only defined commands. This is advantageous because the supplied original reactivation device control data 77 can only trigger one of the defined commands. It is furthermore possible for the reactivation device control logic gate part 78 to only output the commands in the form of reactivation device control result data 79 or for the commands to only be processed if the commands correspond to a defined sequence of commands. This is advantageous because, for example, attacks that represent a high number of repetitions of the same command or the same sequence of commands can be blocked or filtered out. In the event that commands deviating from the defined sequence of commands occur, for example, an alarm signal can be output or the device 1 can be shut down, etc. Furthermore, it can be seen from this embodiment by way of example that the holding device 28 and / or theReactivation device 80 are each connected to the work system 100 or the control device 300 via preferably one or at least one unidirectional data conductor 29, 47, in particular a fiber optic cable. The unidirectional data conductor(s) 29, 47 are preferably designed such that data can be transmitted via them exclusively to the work system 100 or to the control device 300. However, it is also possible for the holding device 28 and the reactivation device 80 to be connected to one another via one or more unidirectional data conductors, in particular for forwarding data, in particular the result data, from the holding device 28 to the reactivation device 80. Fig. 4 corresponds essentially to Fig. 3, wherein the holding device 28 is equipped with a malware checking device, in particular a data checking logic gate or a CPU and / or a GPU.The malware checking device is preferably updateable. Particularly preferably, a lookup table is updated when updating the malware checking device. Preferably, the malware analysis data are converted into other binary sequences analogously to the passivation by the passivation device 2. This preferably also applies to the updates of the malware analysis data. The malware checking device then preferably checks the binary sequences of the digital result data based on the binary sequences of the malware analysis data. The malware checking device preferably compares the binary sequences or parts of the binary sequences of the digital result data and the malware analysis data. Particularly preferably, the malware checking device comprises the data verification logic gate, and the data verification logic gate particularly preferably comprises an updateable lookup table, wherein the malware analysis data and / or the update data are stored in theLookup table are held or provided. Fig. 5 shows an example according to which the passivation device 2, the holding device 28, the data checking device 46 and the reactivation device 80 are designed separately, in particular in their own housings or on separate PCBs or functionally separated from one another on one PCB. However, it is possible for 2, 3 or all of these devices to be provided as a combined device(s). The control of the data checking device 46 is preferably carried out via a data checking device control logic gate part 64, wherein original data checking device control data 63, in particular from the work system 100 or the control device 300, are supplied. The data checking device control logic gate part 64 is preferably implemented at least as an FPGA or ASIC. The data checking device control logic gate part 64 is configured to, based on theOriginal data checking device control data 63 to generate data checking device control result data 65. Preferably, the data checking device control logic gate part 64 only outputs a defined number of commands or only defined commands. This is advantageous because the supplied original data checking device control data 63 can only trigger one of the defined commands. It is further possible for the data checking device control logic gate part 64 to only output the commands in the form of data checking device control result data 65 or for the commands to only be processed if the commands correspond to a defined sequence of commands. This is advantageous because, for example, attacks that represent a high number of repetitions of the same command or the same command sequence can be blocked or filtered out. In the event that commands deviating from the defined sequence of commandsCommands occur, for example, an alarm signal can be issued or the device 1 can be shut down, etc. Furthermore, Fig. 5 shows that the reactivation device 80 is preferably connected to the work system 100 or the control device 300 by means of a unidirectional data conductor 99, in particular a fiber optic cable, in particular for transmitting data, in particular status data of the reactivation device 80, to the work system 100 or the control device 300. Fig. 6 shows an example according to which the control of one or more of the devices, here only the holding device 28 and the reactivation device 80 (but also applies to the data checking device) can be carried out via an analog interface. In this case, the system preferably has at least one control data processing processor for generating a plurality of different analog signals of a control representation type depending on digitalControl source data. The digital control source data preferably represent a plurality of different input commands, in particular from at least one input device or a control device, such as a control device, wherein the plurality of different input commands of the digital control source data are represented by a plurality of different analog signals of the control representation type, wherein the plurality of different analog signals of the control representation type can preferably be generated in a plurality of, in particular at least four, different states, wherein a plurality of or each analog signal of the control representation type of the plurality of different analog signals of the control representation type represents a defined input command, in particular directly or indirectly, wherein the control data processing processor has at least one data interface for receiving the digital control source datawherein the control data processing processor has at least one signal output for outputting the analog signals of the control representation type, a control input signal processing processor for converting the analog signals of the control representation type into the digital control result data for manipulating the digital control result data, wherein the control input signal processing processor has at least one signal input for receiving the analog signals of the control representation type output via the at least one signal output of the control data processing processor, wherein the digital control result data is a digital representation of at least a portion of the analog signals of the control representation type, wherein the control input signal processing processor is coupled at least indirectly to a function processor device for executing or effecting at least one function and preferably a plurality of functions.The analog interface can further be designed according to PCT / EP2022 / 059665. Fig. 7 shows a further example of a data backup and / or provision device 1 according to the invention, wherein control data of one, several or all devices 28, 46, 80 are transmitted via one or more analog interfaces and the analog interface(s) are consequently part of the data backup and / or provision device 1. Fig. 7 consequently shows that the communication paths from the work system 100 or the control device 300 to the respective device (reserve device, data checking device, reactivation device or passivation and reserve unit) of the four previously described embodiments can be effected partially or completely by means of analog interfaces. Fig. 8 shows an example of a logic gate device 200 according to the invention. The logic gate device 200 preferably has one or at least one passivationLogic gate part. The at least one passivation logic gate part 8 is configured to convert digital original data 4 into digital result data 6, wherein the digital result data 6 represents a passivated form of the digital original data 4. The passivation logic gate part preferably has a hold-up device data supply output for outputting the result data to a hold-up device 28. Additionally or alternatively, a hold-up device control logic gate part can be provided. The hold-up device control logic gate part 37 is preferably configured to convert original hold-up device control data into hold-up device control result data. The hold-up device control logic gate part preferably has a hold-up device control data output for outputting the hold-up device control result data. A reactivation logic gate part is preferably provided additionally or alternatively. The reactivation logic gate partis particularly preferably configured to convert the result data into target data 22. The reserve device control logic gate part or a data verification logic gate part preferably has a reactivation device data supply output for outputting the target data to a reactivation device 80. The reactivation logic gate part preferably has a reactivation device data supply input for supplying the result data. Additionally or alternatively, a reactivation device control logic gate part can be provided for controlling the reactivation device 80. The reactivation device control logic gate part is particularly preferably configured to convert original reactivation device control data into reactivation device control result data. Preferably, a reactivation device control data output is provided for outputting the reactivation device control result data. Furthermore, aA reactivation device control data input is provided for supplying the reactivation device control source data. Furthermore, at least one data verification logic gate part is preferably provided. The at least one data verification logic gate 60 is preferably configured to analyze digital result data 6 for malware. A data verification logic gate part preferably compares representative information, in particular binary sequences or parts of the binary sequences of the malware, of the malware stored in a lookup table 62 with the binary sequence or parts of the binary sequence of the source data or performs a comparison according to a defined execution logic, in particular an algorithm. The data verification logic gate part is preferably configured to convert the result data into the source data in a first step and then effect the comparison with the representative information stored in the lookup table 62. FurthermoreA data verification logic gate sub-output or each data verification logic gate sub-output via which the original data generated from the result data can be output to an original data memory and / or the original data memory can be physically separated from the storage device data memory 30 and / or the reactivation device data memory 96, in particular in such a way that malware cannot reach the storage device data memory 30 and / or the reactivation device data memory 96. The original data generated by the data verification logic gate sub-output can preferably be deleted after the comparison, and preferably the memory area on which the data was provided is formatted. Depending on the comparison result, comparison data is preferably generated, wherein the comparison data is assigned to the corresponding result data held in the storage device 28 or the corresponding result data isComparison data are added. The comparison data preferably includes information on the version of the representation information and / or the comparison result. The data verification logic gate part preferably compares binary sequences of malware result data stored in a lookup table 62 with the binary sequence of the result data. The binary sequences of the malware result data stored in the lookup table 62 are preferably generated from malware original data in accordance with the conversion of the original data into the result data. Furthermore, a data verification device control logic gate part can be provided for controlling the data verification device 46, i.e., be a component of the data backup and provision device logic gate device 200. The data verification device control logic gate part is preferably configured to convert original data verification device control data into data verification device control result data. AA data verification device control data output is preferably provided for outputting the data verification device control result data. A data verification device control data input is preferably provided for supplying the data verification device control original data. One or more FPGAs and / or ASICs are provided. Preferably, at least two or exactly two or at least three or exactly three or at least four or exactly four of the logic gates: passivation logic gate part, retention device control logic gate part, reactivation logic gate part, reactivation device control logic gate part, data verification logic gate part and / or data verification device control logic gate part are formed by one or each one or more FPGAs or ASICs. Fig. 9 schematically shows that the retention device 28 has a preferably unidirectional data connection 130, in particular an optical fiber, for transmitting the digital result data.6 to the reactivation device 80. Additionally or alternatively, the holding device 28 can have a preferably unidirectional data connection 29, in particular a fiber optic cable, for transmitting, in particular copying, mirroring, or shifting, the digital result data 6 to a data checking device 46. Furthermore, the work system 100 or the control device 300 can be connected to one another via an update logic gate 128, in particular FPGA or ASIC, for updating the malware identification data. Additionally or alternatively, the holding device 28, the reactivation device 80, and / or the data checking device 46 can be connected to the work system 100 or the control device 300 by means of a unidirectional data connection for transmitting data to the work system 100 or the control device 300. Fig. 10 shows an example of the present invention without a reactivation device, i.e. the dataare exclusively secured and preferably checked for malware. The reactivation of the data can, for example, in the case of data stored in the cloud, be carried out by the actual owner of the data, whereby this owner would then maintain a reactivation device 80. Figs. 11a and 11b show the reactivation device 80 with different degrees of complexity. The reactivation devices 80 shown in accordance with the previously shown embodiments can alternatively be designed according to Fig. 11a or 11b. I.e. the respective reactivation device 80 can, for example, have a reactivation device input interface, a reactivation device data memory and a data processing device. The data processing device of the reactivation device can in this case be, for example, a logic gate, a CPU and / or a GPU. Alternatively (Fig. 11b), the reactivation device 80 can additionally have one or twoMalware analysis devices, wherein one malware analysis device is preferably hardware-based, in particular an FPGA or ASIC, and the other is preferably software-based and is executed by a CPU and / or GPU. Fig. 12 shows a further purely exemplary embodiment, wherein a "host PC", also called work system 100 or control device 300, preferably a server or a computer system for receiving and processing data, is provided. The "host PC" sends a file or general data to the device via an interface such as a Universal Asynchronous Receiver Transmitter (UART). With UART, there is a bidirectional connection consisting of a channel that enables the data to be sent to the device (RX) and a channel that enables the feedback from the UART engine to the output system (TX). The UART engine transmits the data in frames of 8 bits each to an Async FIFO module, which without furtherSynchronization also passes the data in 8 bits to an encoder module. In the encoder module, which can be implemented as a logic gate such as an FPGA, the incoming bits are individually translated into equivalents such as 8-bit ASCII characters. In this case, the data size is increased eightfold. The now 64-bit translated data is passed to a packetizer module. This breaks the total amount of translated data into packets and adds a checksum and other packet components. These packet components are shown in Fig. 13a. These are the bit sequences (SOP and EOP) marking the start and end of the packet, the name and extension of the output file, and the size of the output file. These supplementary packets are passed to the output interface (TX) (see Fig. 13b), which forms the end of the transmit side of the device. Both the output interface (TX) and the first in first out module (Async.FIFOs can provide direct status updates to the input interface (UART) via unidirectional lines and thus control the amount of data provided by the input interface. Alternatively, a memory module could be used to buffer the data traffic. The transmitting side described above is opposed to a receiving side of the device, or a second device configured as the receiving side. The input interface of the receiving side (RX) (see Fig. 13c) is preferably connected unidirectionally to the output interface of the transmitting side (TX). Since the connection between the two interfaces does not have an additional channel for exchanging information such as the clock, a special encoding method can be used for transmission, which integrates the clock into the data stream, as in Manchester encoding, for example. The input interface of the receiving side (RX) (see Fig. 13c) outputs theReceived data packets are forwarded, preferably according to the async. FIFO principle, to a module that checks the individual packets and prepares and resolves them for further processing. The checksum (CRC) and the end-of-packet (EOP) are removed. During the check, the checksum previously added to the packet on the transmitting side is compared with a self-calculated checksum. The result of this comparison is appended to the file packet as a CRC valid value. Using another FIFO module and an interface to a receiving system (here also a host PC), the file packet is transferred to this receiving system, preferably a data server or a hard disk. The transmitting and receiving sides can be implemented as separate units and connected via corresponding network nodes instead of directly. It would also be possible to implement the device in a single component (logic gate) with separate sectors. Fig. 14 shows anotherSchematic example of the data backup and / or provision device 1 according to the invention. Reference numeral 160 preferably denotes a housing which is designed to accommodate the passivation device 2, in particular the passivation logic gate 8, the reactivation device 80, in particular the reactivation logic gate 90, the data processing device 97 and / or the storage device 28, or which comprises the passivation device 2, the reactivation device 80, the data processing device 97 and / or the storage device 28. In addition, the housing 160 can comprise the terminal 150, or the terminal can be formed as part of the housing 160. Additionally or alternatively, an interface can be provided for the preferably direct connection of the terminal 150 to the housing 160 for controlling the data backup and / or provision device 1 and / or for introducing malware signature data.Data processing device 97 can preferably be designed to effect a plurality of functions. The data processing device 97 can, for example, effect the function(s) of one or more of the following devices: data processing device of the storage device, data processing device of the passivation and storage unit, data processing device of the data checking device and / or data processing device of the reactivation device. Particularly preferably, the data processing device 97 can effect the storage of the data provided by the passivation device 2 (arrow P1) and / or preferably the data processing device 97 can effect the transfer of the stored data (which are provided by the passivation device 2) to the reactivation device 80 (arrow P2). Naturally, the data backup and / or provision device 1 has further functions familiar to a person skilled in the art andtherefore includes components not mentioned, such as power supply or switching on / off means, without such components being shown or described in detail. It is not intended to execute the "DATA BACKUP" process (reference numeral 3) simultaneously with the "DATA RECOVERY" process (reference numeral 47), although this may nevertheless be possible. The "DATA RECOVERY" process (reference numeral 47) is preferably only executed if the "Operating System" is encrypted. Thus, after the signature of a malware has been identified, the signature is preferably fed into the system 1 via the terminal 150, and the data processing device 97, in particular CPU, GPU, ASIC, or FPGA, analyzes the representations of individual, several, or all files with regard to this signature. All files that do not contain this signature can be provided to the reactivation device 80 to be decrypted by it and made available to the productive system 100.The reactivation device 80, in particular a logic gate or reactivation logic gate 90, in particular an FPGA or ASIC, is preferably configured to effect the conversion of the result data 6 into the target data 22 depending on the representative data 7 or a part of the representative data 7 or inverse representative data or a part of inverse representative data. "Inverse representative data" describes a version of the representative data prepared in such a way that an "inverse encryption" or decryption of the result data 6 can be effected to generate the target data 22. Figure 15 shows a somewhat more detailed functional diagram of a possible technical implementation of the present invention, in particular of the structure shown in Fig. 14. The logic gate unit 71 preferably represents an interface to the production system 100. The reference numeral 72 denotes, purely by way of example, a data connection MAC,which is functionally coupled at least to a control logic 73 and / or a DMA 75. Furthermore, the DMA 75 and / or the control logic 73 can be coupled to a CPU 74. The DMA 75 is further preferably connected directly or indirectly to a passivation device 2, in particular a logic gate. The receipt of data coming from the production system 100 can, on the one hand, be confirmed by this structure. On the other hand, the data received from the production system 100 can be preconditioned such that they can be generated in a modified form by means of the passivation device 2. The preconditioning preferably comprises the addition of file information and / or the division of the bits of the file into predetermined block lengths, in particular 8-bit blocks or 16-bit blocks or 32-bit blocks or 64-bit blocks or 128-bit, etc., and the feeding of the blocks to the passivation device 2. The passivation device 2, in particular the passivation logic gate 8, is provided with aData processing device 97 is coupled. Furthermore, the passivation device 2 forms the only path via which data from the production system 100 can reach the data processing device 97. The passivation device 2 generates a first encrypted form of the digital original data 4. This first encrypted form can be generated, for example, as described in Fig. 18 / 19. Furthermore, malware signature reference data, in particular relating to one or more malware signatures, can be supplied to the data processing device 97 via the terminal 150, for example, or can be generated by the data processing device 97 depending on the data supplied to the data processing device 97. The data processing device 97 or a part of the data processing device 97 can preferably be provided as an analysis unit for determining malware signature data. The analysis unit is particularly preferably configured toResult data, in particular also based on the representation data assigned to or associated with the respective result data, to generate analysis bit representation data, wherein the analysis bit representation data represent the first bit sequence in encrypted form and wherein the analysis bit representation data can be analyzed with respect to a malicious code signature contained in the first bit sequence or with respect to several malware signature data contained in the first bit sequence. From the first encrypted form, the data processing device 97 can thus preferably generate a second encrypted and analyzable form. This second encrypted form can be generated, for example, as described in Fig. 20 / 21. In addition, Fig. 17 shows an example of a multi-stage change in the bit representations of the original data. The second encrypted form is preferably generated from the first encrypted form and / or alongside the first encrypted form, i.e. the firstThe encrypted form can preferably continue to exist. Alternatively, however, it is also possible for the passivation device 2 to generate the result data 6 in such a way that these represent the analysis bit representation data. In this alternative embodiment, the encryption or coding prior to the analysis would be less extensive, whereby the overall computing effort and memory requirements would also be smaller. Fig. 16 shows, purely schematically, an example of a data backup with subsequent encryption of the work system 100 and an analysis of the data backup with regard to malware and an optional cleanup of the data backup, whereby the infected or compromised files can be deleted and / or moved to quarantine during the optional cleanup. In addition, the data backup or the method underlying the data backup can perform the step of restoring the work system 100 by transferring the data backed up by the data backup.on the work system 100. Especially in a backup situation, the solution according to the invention or data backup and / or provision device 1 or the cyberstorage according to the invention is superior to other solutions. Due to the homomorphic properties, it is possible to completely clean the backup of malicious code after an attack by malware, in particular ransomware, without the data having to be decrypted and thus no risk of re-infection exists. Steps S1-S5 describe the following purely by way of example: S1: Backup of the data. The data is encrypted or encoded by the passivation device 2, in particular the logic gate array (LGA) 2, in the data backup and / or provision device, in particular in the cyberstorage, wherein preferably analyzable data, in particular text representations of the original data, can be generated. S2: The production system 100 is encrypted 501b and the signature 503 of theMalware, in particular ransomware, is identified after the encryption of the production system 100, in particular using forensic methods. S3: The coded or encrypted data, in particular the text representations, in the data storage 30 are analyzed to identify infected data with regard to the determined signature 503. S4: Infected data is deleted or isolated. S5: Restoration of the production system 100 based on a clean backup or individually verified data. Based on the cleaned data, the digital source data or target data 22 of the respective data are generated, preferably by means of a reactivation device 80, in particular the logic gate array (LGA) 2 or another logic gate array. Steps S1-S5 can be assigned to different levels (SI and SII). Level SI is preferably performed for each individual file that is transferred to the cyber storage 1. Level SII concernspreferably the ANALYSIS / RESTORATION of data. These steps are preferably only carried out after the productive system 100 has been attacked, in particular encrypted, by the malware, in particular ransomware, and the signature of the malware, in particular the ransomware, has been determined. In order to prevent an attack on a data backup and / or provision device 1 according to the invention, each file is consequently encrypted, coded, or obfuscated in a preferably random manner. However, since level SI and level SII fulfill different functions, there are different requirements for the encryption, coding, or obfuscating. Preferred requirements for SI: The complexity of the encryption, coding, or obfuscating is preferably very high, since each individual file of each system can also contain very short malware snippets (e.g., less than 20 bits). For example, it isparticularly preferred if the complexity of the first 15 bits of an encrypted file is already higher than 1 / 1000, in particular higher than 1 / 2000 and preferably higher than 1 / 3000 and particularly preferably higher than 1 / 3000 2 and most preferably higher than 1 / 3000 3The encrypted file should preferably be interpretable so that an analyzable version of the encrypted file can optionally be provided in stage SII. After encryption of the production system and before starting stage SII, the data store can preferably be duplicated to another hard drive and separated from the existing system. Preferred requirements for SII: The complexity of encryption, coding, or obfuscation can be significantly reduced due to the duplicate version on a separate hard drive. Even if malware, especially ransomware, were generated through reverse engineering, it would only encrypt the files that have not yet been restored. Consequently, the compromised file would be removed from the duplicate version, and SII can continue.Due to the logic gates, in particular the logic gate array (recovery), (malicious) encryption within the data backup and / or provisioning device 1 cannot spread to the production system 100. The encryption or coding or obfuscation is preferably analyzable to enable the detection of malware so that the malware can be deleted or the file can be isolated / deleted. The complexity of the analyzable encrypted file is preferably higher than 1 / 1000, in particular than 1 / 5000, and preferably higher than 1 / 10000, and particularly preferably higher than 1 / 20000, and most preferably higher than 1 / 49000. Alternatively, however, it is also possible for the SI to be followed only by the recovery, thereby omitting the analysis part. The analysis part can then be carried out on the respectively restored file, for example, using appropriate software, such as a virus scanner / malware scanner from Avira, Kaspersky, etc.It is conceivable here for the file to be restored in a DMZ, where it can be analyzed using a virus scanner / malware scanner. However, the data backup and / or provisioning device 1 according to the invention can alternatively be designed such that the forensic analysis function and the function of deleting or isolating the identified files are only optional or are not present. For example, malware analysis software can be executed on the work system 100, which, for example, after a corresponding update with knowledge or data on the malware, immediately examines the original data of the respective files generated by the reactivation device 80 and, if necessary, i.e., if an infection has been detected, deletes or isolates them.The data backup and / or provision device 1 according to the invention in this case represents a preferably continuously fillable and non-encryptable data backup. The invention can therefore relate to a method for data backup, which preferably comprises the following steps: converting digital original data 4 into digital result data 6 by means of a passivation device 2, wherein the passivation device 2 has at least one passivation logic gate 8 and wherein the at least one passivation logic gate 8 is configured to convert the digital original data 4 into the digital result data 6 and preferably to generate the result data 6, wherein the digital original data 4 is defined by a first binary sequence 16 (cf. Fig. 17), wherein the digital result data is defined by a second binary sequence 18 (cf. Fig.17), wherein the first binary sequence 16 and the second binary sequence 18 are different from one another, and the step of converting the result data into target data 22 by means of a reactivation device 80. Furthermore, according to the invention, the passivation device 2 can, on the one hand, have a passivation device input interface 10 for supplying the original data 4 to the at least one passivation logic gate 8, and, on the other hand, the passivation device 2 can have a passivation device output interface 14 for outputting the result data generated by the at least one passivation logic gate 8 (cf. Fig. 14). The reactivation device 80 can have a reactivation device input interface 84 for supplying the result data to the reactivation device 80 and preferably a reactivation device output interface 86 for outputting the target data 22 (cf. Fig. 14).The target data 22 preferably match the source data, in particular exactly, or preferably at least 90%, at least 95%, at least 99%, at least 99.9%, or exactly 100%. Fig. 17 shows what the bit representation of the source data 4 looks like, for example, on the production system 100 and what it looks like, for example, as an encrypted file 6 (Level 1: Storage (SI)) and during analysis (Level 2: ANALYSIS / RESTORATION (SII)). Level 1 or SI is additionally explained in Fig. 18. If SII is provided, an analysis unit 170 can be provided for determining and / or identifying malware signature data.The analysis unit 170 is preferably configured to generate analysis bit representation data 172 based on result data 6, in particular also based on the representation data 7 assigned to or associated with the respective result data 6, wherein the analysis bit representation data 172 represents the first bit sequence 16 in encrypted form and wherein the analysis bit representation data 172 can be analyzed with respect to a malware signature 503 contained in the first bit sequence 16 or with respect to a plurality of malware signature data 503 contained in the first bit sequence 16. The analysis bit representation data 172 with respect to the zero binary sequence representations 19 of the result data 6, in particular of a result data file, have a plurality of first bit blocks 196 (cf. e.g. Fig.25a) to at least or exactly one zero analysis bit representation 176, in particular of a standardization system 506 (cf. Fig.22), and wherein the analysis bit representation data 172 with respect toThe ones binary sequence representations 20 of the result data 6, in particular of a result data file, comprise a plurality of second bit blocks 197 (cf., for example, Fig. 25a) to at least or exactly one ones analysis bit representation 178, in particular of the standardization system 506 (cf. Fig. 22). The standardization system 506 preferably comprises a plurality of different bit blocks, in particular from a plurality of systems 2. A -2 B , such as2 5 -2 10, wherein each bit block is assigned a unique comparison parameter. Preferably, each of these bit blocks can be used as a zero binary sequence representation 19 or a one binary sequence representation 20 and consequently as a first bit block 196 and a second bit block 197. The comparison parameter can be selected, for example, from the following group of comparison parameters: symbols, colors, grayscale and / or patterns. According to a further preferred embodiment of the present invention, the grayscale or color for each bit block can be optically output by means of at least one pixel or several pixels, in particular 2, 3, 4, 5 or up to 10 or more than 10 or up to 200 pixels.According to a further preferred embodiment of the present invention, 4 or more than 4 or 8 or more than 8 or 16 or more than 16 or 32 or more than 32 or up to 32 or preferably 64 or more than 64 or up to 64 or particularly preferably 128 or more than 128 or up to 128 or most preferably 256 or more than 256 or up to 256 different bit blocks 196, 197 are provided. According to a further preferred embodiment of the present invention, the symbols are embodied as numbers and / or letters and / or characters, in particular numbers and / or letters and / or characters according to ASCII code. An assignment of bit blocks and symbols is, for example:

[0003] According to a further preferred embodiment of the present invention, the colors are 128 different colors or more than 128 different colors, or preferably 256 different colors or more than 256 different colors, or 512 different colors or more than 512 different colors. An assignment of bit blocks and colors is according to a further preferred embodiment of the present invention: 0000000 color value 1 0000001 color value 2 ... 0111111 color value 128. According to a further preferred embodiment of the present invention, the gray levels are 128 different gray levels or more than 128 different gray levels, or preferably 256 different gray levels or more than 256 different gray levels, or 512 different gray levels or more than 512 different gray levels.An assignment of bit blocks and gray levels is according to a further preferred embodiment of the present invention: 0000000 gray value 1 0000001 gray value 2 ... 0111111 gray value 128. 64 gray values ​​are preferred, ie in system 2. 6 , which covers the bit blocks 000000 to 111111. Additionally or alternatively, 128 color values, ie in the system 2 7 , which covers the bit blocks 0000000 to 1111111. Additionally or alternatively, 256 characters, ie in System 2 8 , which means that the bit blocks range from 00000000 to 11111111. Alternatively, it is also possible that only color values ​​and / or gray values ​​are used and that these are spread across several systems 2 A -2 B For example, a first group of color values ​​can comprise 32 color values, ie the system 2 5and consequently comprise the bit blocks 00000 to 11111. In addition, a second group of color values ​​can comprise 64 color values, ie the system 2 6 and consequently comprise the bit blocks 000000 to 111111. In addition, a third group of color values ​​can comprise 128 color values, ie the system 2 7 and consequently comprise the bit blocks 0000000 to 1111111. In addition, a fourth group of color values ​​can comprise 256 color values, ie the system 2 8 and consequently comprise the bit blocks 00000000 to 11111111. In addition, a fifth group of color values ​​can comprise 512 color values, ie the system 2 9 and consequently comprise the bit blocks 000000000 to 111111111. In addition, a sixth group of color values ​​can comprise 1024 color values, ie the system 21 0and consequently comprise the bit blocks 0000000000 to 1111111111. In this example, 2016 different bit blocks are defined and consequently 2016 different optically outputtable colors are defined. The selection of one of the 2016 bit blocks (with the color represented thereby) for the bit "0" and the selection of one of the then remaining 2015 bit blocks (with the color represented thereby) for the bit "1" thus creates a complexity of 2016 * 2015 = 4,062,240. That is, a selection from 4,062,240 possible selection options. The term color value preferably describes an optically outputtable, but particularly preferably at least machine-readable or machine-processable color. The terms color value and hue can be used synonymously. The term gray value preferably describes an optically outputtable, but particularly preferably at least machine-readable or machine-processable gray value. The terms gray value,Grayscale and gray tone can be used synonymously. According to a further preferred embodiment of the present invention, the data backup and / or provision device 1 comprises a data memory, wherein the analysis unit can effect data modification and / or data generation on the data memory and / or the deletion of data and / or the retrieval of data from the data memory. However, it is alternatively also possible in the embodiment shown in Fig. 17 for the passivation device 2, in particular the passivation logic gate 8, to generate or select the zero binary sequence representation 19 and the one binary sequence representation 20.Wherein the zero binary sequence representation 19 and one binary sequence representation 20 are also usable or used as zero analysis bit representation 176 and one analysis bit representation 178. This means that a conversion or recoding or reobfuscation from SI to SII or the zero binary sequence representation 19 and one binary sequence representation 20 into a zero analysis bit representation 176 and one analysis bit representation 178 is not absolutely necessary.since the zero binary sequence representation 19 and one binary sequence representation 20 can be directly generated or defined as an analyzable zero binary sequence representation 190 and an analyzable one binary sequence representation 192. Purely by way of example, Fig. 24 shows how the passivation device 2 generates such an analyzable zero binary sequence representation 190 and an analyzable one binary sequence representation 192. For the purposes of this patent, the term zero binary sequence representation 19 thus includes the analyzable zero binary sequence representation 190, and the term one binary sequence representation 20 includes the term one analyzable one binary sequence representation 192, unless, in addition to the zero binary sequence representation 19 and one binary sequence representation 20, a zero analysis bit representation 176 and one analysis bit representation 178 are also mandatory. The passivation device 2, in particular LGA 1,can thus define or select an analyzable zero binary sequence representation 190 and an analyzable one binary sequence representation 192. In particular, a bit representation combination, in particular an analyzable zero binary sequence representation 190 and an analyzable one binary sequence representation 192, is randomly selected from an "analyzable bit representation look-up table" 189 or, alternatively, determined using an algorithm. Examples of random algorithms (which can also be used in other embodiments of the present invention) are available, for example, here: https: / / infoskript.de / files / infoskript / oopjava / zufallszahlen / algo38.pdf. Alternatively, analogous to the look-up tables shown in Fig.19, the bit representations of the table 189 can be divided into preferably a plurality of different look-up tables, particularly preferably 95 different look-up tables, each preferably having a plurality of positions,particularly preferably 94 positions each (bit representation for "0" and "1" must not be identical), and the passivation device 2, in particular LGA1, selects an analyzable bit representation look-up table entry 194. The bit representations shown in Figures 25a and 25b represent ASCII characters purely as examples. However, it is additionally or alternatively possible for the bit representations to represent gray values ​​or for further bit representations to be provided that represent gray values. However, it is additionally or alternatively possible for the bit representations to represent color values ​​or for further bit representations to be provided that represent color values. For example, bit representations of 128 gray values ​​could be provided,when the 7-digit bit representations 0000000 to 1111111 are linked to it. Additionally or alternatively, bit representations of 512 color values ​​could be provided, for example, when the 9-digit bit representations 000000000 to 111111111 are linked to it. In the case of 95 ASCII characters, 128 gray values, and 512 color values, the available number of analyzable zero binary sequence representations is 735, and the available number of analyzable one binary sequence representations is 734. Fig. 18 shows an example according to which the original file is encrypted, coded, or obfuscated with the aid of the passivation device 2, wherein the passivation device 2 preferably generates the encrypted, coded, or obfuscated file 6 and particularly preferably also one or at least one documentation look-up table 62 (Doc-LuT). The "data to be stored" or the "file to be stored" is represented by bits, i.e., zeros and ones.formed. The passivation device 2 preferably generates an encrypted file 6 (where "encrypted" here means, in particular, "obfuscated"). In addition, the passivation device 2 preferably generates one or at least one or exactly one documentation look-up table 62 with respect to the encrypted file 6. The documentation look-up table 62 has documentation about which bit sequence (sequence 1 to sequence n) has which length and with which bit representation look-up table entry the zeros and ones of the respective bit sequence 185 are translated, encrypted, or obfuscated. Alternatively, it is possible that the length of the bit sequence 185 is always the same, whereby this information may be obsolete. The individual bit representation look-up table entries 184 can, as shown in Fig. 19,Be part of different bit representation look-up tables 186a-n or a single bit representation look-up table 186. The passivation device 2 preferably randomly selects a "bit representation look-up table" 186a-n for each bit sequence 185, in the example shown (see Fig. 19) from LuT-Rep-01 to LuT-Rep-60. Additionally, the passivation device 2 selects a representation combination (gray / black marked fields are preferably not selectable to avoid ambiguity). Example: LuT-Rep-01 No. 21 defines that "0" bits are represented by 0110 and "1" bits by "00"; LuT-Rep-07 No. 45 defines that "0" bits are represented by 00111 and "1" bits by "010"; etc. Alternatively, the passivation device 2 can preferably randomly select a bit representation look-up table entry 184 for each bit sequence 185. In the event that an analysis of the encrypted file 6 is to be possible,The passivation device 2 preferably generates, in particular randomly, a zero analysis bit representation 176 and a one analysis bit representation 178 for preferably each bit sequence 185, or assigns such a zero analysis bit representation 176 and a one analysis bit representation 178 to the respective bit sequence 185. The zero analysis bit representation 176 and the one analysis bit representation 178 can then also be added to the look-up table 62 or be part of another look-up table assigned to the encrypted file 6 or a file assigned to the encrypted file 6 or a table entry assigned to the encrypted file 6. The zero analysis bit representation 176 and the one analysis bit representation 178 can, for example, be selected from the ASCII encoding,wherein particularly preferably only the visually displayable ASCII coding entries are selectable. Purely by way of example, consecutive bits of the "file to be saved" 4 are underlined with four lines of different thicknesses. Each of these lines of different thicknesses indicates the bits of a bit sequence 1-4185. The bit sequence 1 has 10 bits in this example, the bit sequence 2 has 4 bits in this example, the bit sequence 3 has 9 bits in this example, and the bit sequence 4 has 10 bits in this example. Each bit sequence 1-4 is preferably selected by the passivation device 2, in particular randomly.A bit representation look-up table entry 184 is assigned, or the zero binary sequence representation 19 and one binary sequence representation 20 stored in the respective bit representation look-up table entry 184 are linked to the respective bit sequence. In the present example, the bit representation look-up table entry 184 "LuT-Rep-06 No. 5" (see Fig. 19) is selected for bit sequence 1, whereby the zero binary sequence representation 19 is "000" and the one binary sequence representation 20 is "001." For bit sequence 2, the bit representation look-up table entry 184 "LuT-Rep-05 No. 22" (see Fig. 19) is selected in the example shown, whereby the zero binary sequence representation 19 is "1010" and the one binary sequence representation 20 is "000". It can be seen,that the individual zero binary sequence representations 19 and the one binary sequence representations 20 of the individual bit sequences can differ in terms of the respective length (number of bits) and the respective bit sequence, resulting in a high level of complexity. The passivation device 2, in particular the passivation logic gate 8, is thus preferably configured to generate, select, or determine zero binary sequence representations 19 for zeros of the first binary sequence 16 of the digital original data 4, and wherein the passivation device 2, in particular the passivation logic gate 8, is configured to generate, select, or determine one binary sequence representations 20 for ones of the first binary sequence 16 of the digital original data 4. The zero binary sequence representation 19 preferably has at least two bits and preferably more than 2 bits,in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits. The ones binary sequence representation preferably has at least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits,With regard to the encrypted file 6, in the present example, the respective encrypted, coded, or obfuscated representation 188 of the respective bit sequence is marked with dashed lines of varying thickness. The encrypted or coded or obfuscated representation 188 of the bit sequence 1 is therefore: 000000001000000000000001000000. The encrypted or coded or obfuscated representation 188 of the bit sequence 2 is therefore: 1010000101010. The encrypted or coded or obfuscated file 6 or the result data 6 is or are composed of the encrypted or coded or obfuscated representation 188 of the bit sequences 1-n, wherein the encrypted or coded or obfuscated representation 188 of the individual bit sequences is preferably in the order in which the bit sequences occur one after the other,be saved. In this example, therefore, bits 1-33 (0010000100010000000000011111001010) of file 4 to be saved are represented by new bits 1-98 (00000000100000000000000010000001010000101010011011 0110110110110110110110111110000000111110011100111) of the encrypted or encoded or obfuscated file 6 or the result data 6. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to define, provide, determine, generate, or select different zero binary sequence representations 19 and / or one binary sequence representations 20 for different source data 4a-n, in particular different files 4, in particular source data to be processed sequentially. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to generate result data 6 with respect to the source data 4, in particular the first binary sequence 16.to define or provide or determine or generate or select different zero binary sequence representations 19 and / or one binary sequence representations 20. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to select, in particular randomly, a bit representation look-up table entry 184, in particular one or at least or exactly one bit representation look-up table entry 184 (cf. Fig. 19) per bit sequence in a look-up table, in particular a bit representation look-up table 186, or in several look-up tables, in particular several bit representation look-up tables 186a-n, with a plurality of preferably defined zero-one binary sequence representation combinations. The one look-up table or the several look-up tables preferably have at least 10,in particular at least 100, and preferably at least 1000, and particularly preferably more than 3000, and most preferably more than 5000 or 10000, different zero-one binary sequence representation combinations. The look-up table 186 or the look-up tables 186a-n is / are provided or stored or deposited in a memory device of the passivation device. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to generate result data 6 with respect to the original data 4 of a file, wherein the result data 6 can be generated with a plurality of mutually different zero binary sequence representations 19, wherein the mutually different zero binary sequence representations 19 have bit sequences of different lengths and / or different bit sequences of the same length. The passivation device 2, in particular the passivation logic gate 8, is preferably configuredto generate result data 6 with respect to the source data 4 of a file, wherein the result data 6 can be generated with a plurality of mutually different one-bit binary sequence representations, wherein the mutually different one-bit binary sequence representations 20 have bit sequences of different lengths and / or different bit sequences of the same length. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to generate result data 6 with respect to the source data 4 of a file, wherein the result data 6 can be generated with a plurality of mutually different one-bit binary sequence representations 20, wherein the mutually different one-bit binary sequence representations 20 have bit sequences of different lengths and / or different bit sequences of the same length, and wherein the passivation device 2, in particular the passivation logic gate 8, is preferably configuredto generate the result data 6 with a plurality of mutually different zero binary sequence representations 19, wherein the mutually different zero binary sequence representations 19 have bit sequences of different lengths and / or different bit sequences of the same length, wherein the bit sequences of the result data 6, in particular for each bit sequence 185, for the zero binary sequence representations 19 and the one binary sequence representations 20 are different from one another. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to generate representative data 7 for the result data 6 or with respect to the result data 6, wherein the representative data 7 indicates which zero binary sequence representations 19 and / or one binary sequence representations 20 the result data 6, in particular the respective concrete result data file, has. The representative data 7 preferably indicateswhich zero binary sequence representations 19 and / or which one binary sequence representations 20 form the result data 6 at which position in the result data 6. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to divide the first binary sequence 16 into bit sequences 185 or original data bit sequences 185, wherein the original data bit sequences 185 have a plurality of bits, wherein the plurality of bits consists of one "0" bit or several "0" bits and one "1" bit or several "1" bits or of "0" bits or of "1" bits. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to store the number of bits of each original data bit sequence 185 in the representative data 7. The passivation device 2, in particular the passivation logic gate 8,is preferably configured to store a bit representation combination 187 or zero-one binary sequence representation combinations 187 in the representative data 7 for each original data bit sequence 185,in particular to generate or select. Preferably, each bit representation combination 187 has a zero binary sequence representation 19 for all "0" bits of an original data bit sequence 185 or a link with a zero binary sequence representation 19, and preferably, each bit representation combination 187 has a one binary sequence representation 20 for all "1" bits of the same original data bit sequence 185 or a link with a one binary sequence representation 20. Additionally or alternatively, each bit representation combination preferably has a zero-one binary sequence representation combination 187 for all "0" bits and "1" bits of an original data bit sequence 185 or a link with a zero-one binary sequence representation combination 187. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to divide the first n bits of the first binary sequence 16 into original data bit sequences 185a-n,whose average number of bits is preferably less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the first n bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than 500 bits and most preferably less than 200 bits. Additionally or alternatively, the passivation device 2, in particular the passivation logic gate 8, is preferably configured to divide the last m bits of the first binary sequence 16 into original data bit sequences 185 whose average number of bits is preferably less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the last m bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than 500 bits and most preferably less than 200 bits. The passivation device 2, in particular the passivation logic gate 8,is preferably configured to divide the first n bits of the first binary sequence 16 into original data bit sequences 185, the number of bits of which is between 2 bits and 50 bits, in particular between 4 bits and 20 bits, and preferably between 5 bits and 15 bits. Additionally or alternatively, the passivation device 2, in particular the passivation logic gate 8, is preferably configured to divide the last m bits of the first binary sequence 16 into original data bit sequences 185, the number of bits of which is between 2 bits and 50 bits, in particular between 4 bits and 20 bits, and preferably between 5 bits and 15 bits. This embodiment is advantageous because it results in a very high level of complexity and consequently security. The passivation device 2, in particular the passivation logic gate 8, is preferably configured to divide the bits between the first n bits,in particular, for example, 100 bits or 500 bits or up to 500 bits or 1,000 bits or up to 1,000 bits or 10,000 bits or up to 10,000 bits, of the first binary sequence 16 and the last m bits, in particular, for example, 100 bits or 500 bits or up to 500 bits or 1,000 bits or up to 1,000 bits or 10,000 bits or up to 10,000 bits, of the first bit sequence 16 into original data bit sequences 185 whose average number of bits is preferably greater than 20 bits, in particular greater than 50 bits or greater than 100 bits. This embodiment is advantageous because, due to the longer bit sequences 185, less memory is required. Preferably, the number of different zero binary sequence representations 19 and the number of different ones binary sequence representations 20 per result data 6, in particular per result data record or result data file,be the same or different. The representative data 7 can preferably be generated as part of the result data 6 or as part of a result data set. Alternatively, the representative data 7 can be generated as a separate data set associated with the result data 6. The passivation device 2, in particular the passivation logic gate 8, is preferably configured, in particular randomly, to predetermine a zero analysis bit representation 176 with respect to the zero binary sequence representations 19 of the first binary sequence 16, and the passivation device 2, in particular the passivation logic gate 8, is preferably configured, in particular randomly, to predetermine a one analysis bit representation 178 with respect to the one binary sequence representations 20 of the first binary sequence 16. The passivation device 2, in particular the passivation logic gate 8,is preferably configured to generate the specification of the zero analysis bit representation 176 and the one analysis bit representation 178 as part of the result data 6 and / or as part of the representation data 7 and / or as part of the analysis bit representation data 172. Alternatively, the analysis unit 170 (cf. Fig. 17) can, on the one hand, be configured to randomly specify, determine, or select at least one or exactly one zero analysis bit representation 176 for generating the analysis bit representation data 172 with respect to the zero binary sequence representations 19 of the first binary sequence 16, and on the other hand, the analysis unit 170 can be configured to randomly specify, determine, or select at least one or exactly one one analysis bit representation 178 for generating the analysis bit representation data 172 with respect to the one binary sequence representations 20 of the first binary sequence 16. The passivation device 2, in particular the passivation logic gate 8,is additionally or alternatively preferably configured to execute an algorithm for the predetermined definition, generation, determination, or selection of the zero binary sequence representations 19 and / or the one binary sequence representations 20, or the passivation device 2, in particular the passivation logic gate 8, is preferably configured to execute a random algorithm for the random definition, generation, determination, or selection of the zero binary sequence representations 19 and / or the one binary sequence representations 20. Fig. 19 shows a plurality of look-up tables, wherein the plurality of look-up tables preferably comprise a plurality of zero-one binary sequence representation combinations 187, wherein the zero-one binary sequence representation combinations 187a-n comprise zero bit representations 19 and one bit representations 20,wherein at least individual zero bit representations 19 of the zero-one binary sequence representation combinations 187 each have a first number of bits, and wherein at least individual one bit representations 20 of the zero-one binary sequence representation combinations 187 each have a second number of bits, wherein at least for individual zero-one binary sequence representation combinations 187, the first number of bits and the second number of bits are the same and / or wherein at least for individual zero-one binary sequence representation combinations 187, the first number of bits and the second number of bits are different. Consequently, a data backup device 1, in particular a data backup and provision device 1, or a cyber storage device is disclosed, at least comprising a passivation device 2 for converting digital source data 4 into digital result data 6.wherein the passivation device has at least one passivation logic gate 8 and wherein the at least one passivation logic gate 8 is configured to convert the digital original data 4 into the digital result data and to generate the result data, wherein the digital original data 4 is defined by a first binary sequence 16, wherein the digital result data is defined by a second binary sequence 18, wherein the first binary sequence 16 and the second binary sequence 18 are different from one another, a reactivation device 80 for converting the result data into target data 22 that matches the original data. This data backup device is particularly preferably used to carry out a method according to the invention for data backup, which preferably has at least the steps of: converting digital original data 4 into digital result data 6 by means of a passivation device,wherein the passivation device comprises at least one passivation logic gate 8 and wherein the at least one passivation logic gate 8 is configured to convert the digital original data 4 into the digital result data and to generate the result data, wherein the digital original data 4 is defined by a first binary sequence 16, wherein the digital result data is defined by a second binary sequence 18, wherein the first binary sequence 16 and the second binary sequence 18 are different from each other,Converting the result data into target data 22 that matches the original data by means of a reactivation device 80. The reactivation device 80 preferably has a reactivation device input interface 82 for supplying the result data to the reactivation device 80 and preferably a reactivation device output interface 86 for outputting the target data 22. The target data 22 preferably match at least 90%, or at least 95%, or at least 99%, or at least 99.9% or particularly preferably exactly 100% with the original data. This means that the bit sequence of the original data 4 and the bit sequence of the target data 22 generated from the result data 6 preferably match or are identical. The passivation device 2 preferably has a passivation device input interface 10 for supplying the original data to the at least one passivation logic gate 8, and the passivation device 2 has a passivation device output interface 14 for outputting the result data generated by the at least one passivation logic gate 8. Fig. 20 shows the encrypted file 6 on the left side of the image, in particular with the look-up table 62 contained therein or assigned thereto. The look-up table preferably represents the length of the individual bit sequences 1-n and the respective representation for "0" and "1". Furthermore, the look-up table 62 can already contain the information,into which zero analysis bit representation 176 and into which one analysis bit representation 178 the respective zero binary sequence representation 19 and one binary sequence representation 20 are to be translated. Based on the look-up table entries, a machine-processable representation for each "0" bit and each "1" bit, in particular as a character / symbol or gray value or color value, is generated in a processing editor. The processable representation can be text, for example. The processing submission, in particular processing editor or text editor or word processing device 171,In this example, the analysis unit 170 generates analyzable text based on an encrypted file 6 and a documentation look-up table 62. The generated text represents (!) bits of the original file. The analysis unit 170 thus preferably generates text and / or gray and / or colored pixels using the processing device 171 by translating the bits of the encrypted file 6 depending on the documentation of the Doc-LuT 62. Therefore, the processing device 171 of the analysis unit 170 receives as input the length of sequence 1, which is 10 bits. Furthermore, the processing device 171 reads from sequence 1 that the text symbol "0" is represented by 000 and the text symbol "1" by 001. The analysis unit 170 generates text symbols "0" and "1" in the processing device 171 untiluntil sequence 1 is completely translated (cf.: Translation of sequence 1). Next, the processing device 171 receives as input the length of sequence 2, which is 4 bits. Furthermore, the processing device 171 reads from sequence 2 that the text symbol "0" is represented by 1010 and the text symbol "1" by 000. The analysis unit 170 generates text symbols "0" and "1" until sequence 2 is completely translated (cf.: Translation of sequence 2). This routine is executed untiluntil all bits of the encrypted file 6 are translated into text symbols or grayscale values ​​or color values. The text created by the processing device 171 is: 0010000100001000000000011111001010 The text created by the processing device 171 preferably corresponds to the bits of the "file to be saved": 0010000100001000000000011111001010 The bit representation of the text created by the processing device 171 in memory is: 0000000000000000000000010 ... 0 ... on Fig.20) Fig.21 essentially corresponds to Fig.20,where only the zero analysis bit representation 176 and the one analysis bit representation 178 are different from those used in Fig.20. The text created by the processing device 171 is: (where in this special case the "0" is represented or reproduced by ASCII + and the "1" by ASCII D) ++D+++++D+++++D++++++++++DDDDD++D+D+ The text created by the processing device 171 preferably corresponds to the bits of the "file to be saved": 0010000100001000000000011111001010 The bit representation of the text created by the processing device 171 in memory is: (Since "ASCII +" is defined by the first bit block 196 "00101011" and "ASCII D" by the second bit block 197 "01000100",the following sequence results) 0010101100101011010001000010101100101010110010101011001010101100101010110010100010000 101011001010110010101011001010101011001010101011001010100010000101011001010101100101010110010 101100101011001010110010101011001010101100101010110010101011001010100010001000100010001 000100010001000100001010110010101101000100001010110100010000101011 (this is the analysis bit representation data 172). Figure 22 shows, on the left, an example of how comparison data 505 can be generated from the malware signature data. Figure 22 also shows, on the right, how the analysis bit representation data can be examined using the comparison data 505 to determine whether it contains the malware signature. In particular, after the analysis bit representation data of a file has been analyzed to determine whether a specific malware signature—in particular, the malware signature of the malware used to encrypt the production system—is contained in the analysis bit representation data and it has been determined,If the analysis bit representation data of this file does not contain the malware signature, the file can be translated or decrypted by the reactivation device 80 for transmission to the production system 100 into target data 22 that matches the original data 4. The reactivation device 80 can be configured to generate the target data 22 based on the analysis bit representation data. Alternatively, the reactivation device 80 can be configured to generate the target data 22 based on the result data, in particular taking into account the representation data 7. Malware signature data can be retained, in particular stored, in the data memory 28 of the data backup and / or provision device 1 or the cyberstorage 1 according to the invention. The malware signature data 503 can preferably be provided as malware signature reference data 182, in particular by the analysis unit 170. The analysis unit 170 is preferably configuredto generate comparison data 505 for comparison with the analysis bit representation data 172 based on the malware signature reference data 182. The comparison data 505 can preferably be generated corresponding to the at least one and preferably exactly one zero analysis bit representation 176 or the zero binary sequence representation 19, in particular the analyzable zero binary sequence representation 190, and corresponding to the at least one or preferably exactly one one analysis bit representation 178 or the one binary sequence representation 20, in particular the analyzable one binary sequence representation 192. Based on the "Malware Signature" reference file 182 and a translation definition, in particular, for example, the ASCII definition of each Doc-LuT, a translation of the malware signature is created for each encrypted file 6, in particular by the passivation device 2 or the analysis unit 170. This means that the malware signature is standardized,by translating it according to the first bit block 196 and the second bit block 197. The preferably two and particularly preferably exactly two mutually different characters, gray value(s) and / or color value(s), by which the processing device 171, in particular the processing editor, in particular the color, grayscale, and / or character editor, outputs, in particular represents, the first binary sequence 16 in a machine-processable, in particular optically outputtable manner, correspond to the two mutually different characters, gray value(s) and / or color value(s), on the basis of which the comparison data 505 were generated or from which the comparison data 505 consists. For the purposes of the entire disclosure, the term gray value can also be replaced by the term gray tone, and the term color value can be replaced by the term hue (the same applies to the respective plural). Preferably, in the "Created Text" (cf. Fig. 20 and Fig. 21) or with the "Created Text",which represents the first binary sequence 16 or at least parts of the first binary sequence 16, during the file analysis step, the search for the character string defined by the comparison data 505 in the "created text". The "created text" can also have grayscale values ​​and / or color values, in particular individual or multiple pixels, or consist entirely of them, i.e., without characters and / or other symbols. This means that the "created text" does not have to be text, but can consist purely of pixels or of a combination of pixels and text. If the comparison data 505 is found in a "created text", this file is preferably treated separately, in particular deleted or moved to quarantine. However, it is particularly preferred to preventthat this file or the file containing the malware signature (i.e., the encrypted file 6 and / or the analysis bit representation data 172 of this encrypted file 6) is prevented from being reactivated by the reactivation device. In the example shown, the zero analysis bit representation 176 or the zero binary sequence representation 19, in particular the analyzable zero binary sequence representation 190, and correspondingly the at least one or preferably exactly one one analysis bit representation 178 or the one binary sequence representation 20, in particular the analyzable one binary sequence representation 192, are represented as characters or symbols, in particular ASCII characters, and are contained by the corresponding bit blocks in the memory. Additionally or alternatively, however, color values ​​and / or gray values ​​can also be represented as the zero analysis bit representation 176 or the zero binary sequence representation 19,in particular, the analyzable zero binary sequence representation 190, and correspondingly as the at least one or preferably exactly one one analysis bit representation 178 or the one binary sequence representation 20, in particular the analyzable one binary sequence representation 192. It is also conceivable that the malware signature data 503 can be provided as a malware signature comparison table (not shown), wherein the analysis unit 170 can be configured to select comparison data from the malware signature comparison table for comparison with the analysis bit representation data 172. Fig.23 shows that the data backup and / or provision device 1 according to the invention or the cyber storage 1 according to the invention for restoring the respective file 9, ie for generating a "restored file" 9 which corresponds to the respective "file to be stored" 4, or corresponds substantially or exactly,and is preferably identical, a reactivation device 80 is used (see Fig. 14). The reactivation device 80 can be implemented as a GPU or CPU, wherein the reactivation device 80 is preferably designed as a logic gate device or logic gate unit. Preferably, the reactivation device 80 and the passivation device 2 can be part of the same logic gate device, in particular FPGA or ASIC, or can consist of different or separate logic gate devices, in particular FPGA or ASIC. The reactivation device 80 preferably generates a "Recovered File" by writing bits to the production system 100 depending on the "Encrypted File" 6 and the Doc-LuT 62, wherein the reactivation device 80 is configuredto process the look-up table "backwards". The documentation look-up table (Doc-LuT) preferably represents a key or a guide for decoding or deobfuscating the sequences S1 to S, nrepresented data. This means that the first sequence 0000000010000000000000001000000 of encrypted file 6 is translated according to Doc-LuT sequence 1 ("0" = 000; "1" = 001) until 10 bits are recovered: Result: 0010000100. Sequence 1 is underlined on the left side of the image with the same line as the recovered result on the right side of the image. The second sequence 1010000101010 of encrypted file 6 is translated according to Doc-LuT sequence 2 ("0" = 1010; "1" = 000) until 4 bits are recovered: Result: 0100. Sequence 2 is underlined on the left side of the image with the same line as the recovered result on the right side of the image. The third sequence 0110110110110110110110110111111 of the encrypted file 6 is translated according to Doc-LuT Sequence 3 ("0" = 011; "1" = 11111) until 9 bits are recovered: Result: 000000001. Sequence 3 is underlined on the left side of the image with the same line as theThe recovered result is shown on the right side of the image. The fourth sequence, 000000001111110011100111 of encrypted file 6, is translated according to Doc-LuT Sequence 4 ("0" = 111; "1" = 00) until 10 bits are recovered: Result: 1111001010. Sequence 4 is underlined on the left side of the image with the same line as the recovered result on the right side of the image. Etc. The underlines on the left and right sides of the image are intended only to facilitate comprehension; they have no technical effect. In the event that the encrypted file 6 was generated using one or at least one or more than one analyzable zero binary sequence representation and one or at least one or more than one analyzable one binary sequence representation, the look-up table may have fewer entries; in particular, in this case, no sequence lengths need to be specified. In this case, preference is given toFor example, only a first bit block 196 and a second bit block 197 are used, which means that splitting into several sequences would not be necessary. List of reference symbols: 6 digital result data / "encrypted file" 1 data backup and / or provision device / / 7 representation data cyber storage 8 passivation logic gate 2 passivation device (LGA1) 9 digital recover data / 3 data channel from the productive system, "restored file" preferably unidirectional 10 passivation device input interface 4 digital original data / "file to be saved" 14 passivation device output interface first binary sequence 42 retention unit output interface of the passivation and second binary sequence retention unit zeros binary sequence representation 44 data processing device of the ones binary sequence representation passivation and retention unit target data 46 data verification device original retention 47 return channel, in particulardevice control data unidirectional, of the data checking device to the holding device- work system or control result data control device, in particular holding device for transmitting status data of the data checking device data channel, in particular unidirectional, of the 48 data checking device holding device to the input interface of the work system or 49 data checking device control device, in particular output interface for transmitting status data of the holding device 50 data processing device of the data checking device holding device data memory 51 update channel for updating the update channel for updating the malware identification data malware identification data 52 data checking device holding device input data memory interface 54 update device data channel from the data checking logic gate to the 56 malware representation data holding device oradditionally 58 Malware representation data or alternatively to the binary sequence reactivation device 60 Data verification logic gate Retention device output interface 62 Lookup table Data channel, in particular 63 Original data verification - unidirectional, from device control data Retention device to the data verification logic gate 64 Data verification device control logic gate part Data processing device of the retention device 65 Data verification device control result data Retention device control logic gate part 66 Data verification device control data output Passivation and retention unit 70 Data connection, in particular Retention unit data memory Ethernet connection 71 Logic gate unit Data connection MAC Reactivation device to work system or control logic Control device, in particular CPU for transmitting status data of the reactivation device DMA 100 Work system / production systemOriginal reactivation device (PC or server) control data 120 Control path via analog reactivation device interface from control logic gate part control device or reactivation device work system to control result data holding device reactivation device (LGA 2) 122 Control path via analog interface from data conductor control device or work system to reactivation device data checking device input interface 124 Control path via analog reactivation device output interface interface from control device or update device of the work system to the reactivation device reactivation device data processing device of the 126 Unidirectional mirroring of the result data generated by the reactivation device on the data checking device data channel from the holding device to the 128 Update logic gate, in particular reactivation logic gate FPGA, for updating theMalware identification data Data channel from the reactivation logic gate to the 130 data channel, in particular reactivation device unidirectional, in particular optical fiber, for forwarding the result data to the first reactivation device data memory 134 alternative or optional second reactivation device return channel from the data memory data checking device to the holding device, wherein the reactivation device return channel has an analog interface data memory (92+94) data processing device, 136 alternative or optional, in particular CPU and / or GPU return channel from and / or ASIC and / or FPGA reactivation device to the sandbox / DMZ data checking device, wherein the return channel has a data channel, in particular analog interface unidirectional, from a first part of the passivation logic gate 192 analyzable onesBinary sequence representation FPGA 194 Analyzable bit representation-b second part of the passivation look-up table entry logic gate, in particular second FPGA 196 first bit block terminal 197 second bit block housing 200 data backup and provision device comparison parameters logic gate device analysis unit / 300 control device processing device, in particular processing editor, 400 update server, in particular color, grayscale, 500 data processing, in particular and / or character editor saving, changing, processing device analyzing and / or deleting analysis bit representation data 501a with malware, in particular ransomware, encrypted file zero analysis bit representation 501b with malware, in particular ones analysis bit representation ransomware, encrypted files / system text representation of the bits of the "file to be saved" 502 introduction of the malware or malware signature data Text representation of the bits of theand / or selection of one or more files and / or malware signature and / or starting the analysis and / or starting the bit representation look-up reactivation table entry 503 Malware or malware bit sequence or original data signature bit sequence 504 Malware or malware on bit representation look-up signature representation bit sequence tables 505 Comparison data zeros-ones 506 Standardization system binary sequence representation combinations SOP Start of packet encrypted or coded or obfuscated representation of the respective bit sequence File name File name File size Analysis bit representation look-up table EOP End of packet CRC32 Cyclic analyzable zeros Redundancy check Binary sequence representation Ftbs File to be saved Ftbr Recovered file P1 Arrow between P2 Arrow between passivation device 2 Data processing device and ng 96 and data processing facility reactivation facility ng 9780

Claims

Claims 1. Data backup device (1), in particular a data backup and provision device (1), comprising at least one passivation device (2) for converting digital source data (4) into digital result data (6), wherein the passivation device has at least one passivation logic gate (8), and wherein the at least one passivation logic gate (8) is configured to convert the digital source data (4) into the digital result data and to generate the result data, wherein the digital source data (4) is defined by a first binary sequence (16), wherein the digital result data is defined by a second binary sequence (18), wherein the first binary sequence (16) and the second binary sequence (18) are different from one another, a reactivation device (80) for converting the result data into target data (22) that matches the source data. 2.Device according to claim 1, characterized in that the passivation device (2) has a passivation device input interface (10) for supplying the original data to the at least one passivation logic gate (8), and wherein the passivation device (2) has a passivation device output interface (14) for outputting the result data generated by the at least one passivation logic gate (8), wherein the passivation device input interface (10) is connected to the passivation device output interface (14) for forwarding digital signals exclusively via the at least one passivation logic gate (8).Device according to claim 1 or 2, characterized in that the passivation device (2), in particular at least the passivation logic gate (8), is part of a data backup and provision device logic gate device, in particular a field programmable gate array (FPGA) or application-specific integrated circuit (ASIC) or complex programmable logic device (CPLD) or simple programmable logic device (SPLD).

4. Device according to one of the preceding claims, characterized in that a holding device (28) is provided.

5. Device according to claim 4, characterized in that. the holding device (28) has a holding device data memory (30) for storing the result data (6).

6. Device according to claim 5, characterized in that the passivation device output interface (14) is connected at least indirectly, in particular directly or indirectly, to a holding device input interface of the holding device (28).

7. Device according to claim 5 or 6, characterized in that the holding device input interface is connected to the holding device data memory (30), and wherein a holding device input interface (32) of the holding device (28) is provided, wherein the holding device input interface (32) is connected to the holding device data memory (30). 8.Device according to claim 5 or 6 or 7, characterized in that result data stored in the holding device data memory (30) of the holding device (28) by a data processing device (36), in particular a data processing device of the holding device (28), can be forwarded to the reactivation device (80), in particular via a bidirectional or unidirectional data connection, in particular by means of at least or precisely one optical fiber, wherein the data processing device (36), in particular the data processing device (36) of the holding device (28), is preferably one or at least one CPU and / or GPU or one or at least one logic gate, in particular an FPGA, or a part of a logic gate, in particular a part of an FPGA. 9.Device according to claim 5 or 6 or 7 or 8, characterized in that the provision device (28) has a provision device communication interface, wherein the provision device communication interface is connected to the work system (100) or the control device by means of a unidirectional data connection, in particular by means of at least or precisely one optical fiber, for transmitting status data of the provision device (28).

10. Device according to claim 9, characterized in that the status data represent at least the memory utilization, the power utilization and / or the number of files stored in the provision device data memory (30) and / or the names of the files stored in the provision device data memory (30) and / or documentation of executed commands.Device according to one of claims 4 to 10, characterized in that the passivation device and the holding device (28) are part of a passivation and holding unit (38).

12. The device according to claim 11, characterized in that the passivation device output interface (14) is connected to a retention unit data memory (40) of the passivation and retention unit (38) for supplying the input data.

13. The device according to claim 12, characterized in that a retention unit output interface (42) of the passivation and retention unit (38) is provided, wherein the retention unit output interface is connected to the retention unit data memory (40).

14. The device according to claim 13, characterized in that result data stored by a data processing device (44) of the passivation and retention unit (38) in the retention unit data memory (40) of the passivation and retention unit (38) can be forwarded to the reactivation device (80), in particular via a bidirectional or unidirectional data connection, in particular by means of at least or precisely one optical fiber.Device according to one of claims 2 to 14, characterized in that a data checking device (46) is provided for detecting malware.

16. Device according to claim 15, characterized in that the data checking device (46) has a data checking device input interface (48) for supplying the result data to a data processing device (50), in particular a data processing device (50) of the data checking device (46), for detecting malware in the result data.

17. Device according to claim 15 or 16, characterized in that the data checking device (46) has a data checking device output interface (49) for outputting the result data checked by the data processing device (50) and / or for outputting a check result. 18.Device according to claim 15 or 16 or 17, characterized in that the data checking device input interface (48) for forwarding digital signals and / or data is preferably connected to the data checking device input interface (48) exclusively via the data processing device (50).

19. The device according to claim 18, characterized in that the data verification device (46) comprises at least one CPU and / or GPU and / or FPGA and / or ASIC as a data processing device.

20. The device according to claim 19, characterized in that the data verification device (46) is configured as a processor device for controlling the functions of the data verification device (46) and / or for effecting a data exchange with at least one further device, in particular a work system and / or a control system and / or a data backup and provision device logic gate device (200) and / or the passivation device and / or the retention device (28) and / or a passivation and retention unit (38). 21.The device according to claim 20, characterized in that the data verification device (46) has at least one data verification logic gate (60) as a data processing device, and wherein the at least one data verification logic gate (60) is configured to detect malware in the result data.

22. The device according to claim 20 or 21, characterized in that the data verification device input interface (48) is connected to the data verification device output interface (49) for forwarding digital signals exclusively via the at least one data verification logic gate (60). 23.Device according to claim 21 or 22, characterized in that the data verification logic gate (60) sends a signal to the retention device (28) or the passivation and retention unit (38) depending on a verification result of the result data, in particular of the concrete result data file, and the retention device (28) or the passivation and retention unit (38) identifies the result data, in particular the concrete result data file, as contaminated or non-contaminated or assigns it to a memory area provided for contaminated result data, in particular contaminated result data files, or assigns it to a memory area provided for non-contaminated result data, in particular contaminated result data files. 24.Device according to claim 20, characterized in that the data processing device (50), in particular the data processing device (50) of the data checking device (46), has at least one data checking logic gate (60), wherein the data checking device (46) has a data checking device data memory (52), wherein in the. Malware representation data (56) is or can be provided in the data checking device data memory (52).

25. The device according to claim 24, characterized in that the malware representation data (56) can be updated by means of an update device (54).

26. The device according to claim 25, characterized in that the malware representation data (56) of a piece of malware has a malware representation data binary sequence (58), wherein the malware representation data binary sequence (58) is different from the binary sequence of the malware.

27. Device according to claim 26, characterized in that the malware representation data binary sequence (58) is longer than the binary sequence of the malware, in particular the malware representation data binary sequence (58) is at least by a factor of 1.2 or a factor of 1.6 or a factor of 2 or a factor of 4 or a factor of 8 longer than the binary sequence of the malware,and / or all contiguous bit sequences of the malware binary sequence with a length of at least 0.001%, in particular at least 1% or preferably at least 10% or most preferably at least 20%, of the total length of the malware binary sequence are different from all contiguous bit sequences of the malware representation data binary sequence (58) with a length of at least 0.001%, in particular at least 1% or preferably at least 10% or most preferably at least 20%, of the total length of the malware binary sequence and / or contiguous bit sequences of the malware binary sequence with a length of at least 32 bits, in particular at least 64, at least 128, at least 256 or at least 512 bits, of all contiguous bit sequences of the malware representation data binary sequence (58) with a length of at least 32 bits, in particular at least 64, at least 128, at least 256 or at least 512 bits,are different.

28. Device according to one of claims 21 to 27, characterized in that the data verification logic gate (60) is connected to the data verification device data memory (52) for data processing, in particular for reading.

29. Device according to one of claims 21 to 28, characterized in that the data verification device data memory (52) has at least one lookup table (62), wherein the lookup table (62) has malware representation data (56) for one or for exactly one or more malware.

30. Device according to one of claims 21 to 29, characterized in that the data verification device (46) is configured to perform a comparison of the malware representation data (56) and the result data.

31. Device according to one of claims 21 to 30, characterized in that the binary sequence of the original data can be converted into the result data according to a first logic, and the malware representation data can be generated from the bit sequences of the malware according to the first logic. 32.Device according to one of claims 21 to 31, characterized in that the result data preferably represent machine-readable character encoding, wherein the character encoding is preferably a 2-bit character encoding or a 3-bit character encoding or a 4-bit character encoding or a character encoding with more than 4 bits, in particular 7, 8, or 18 bits, in particular American Standard Code for Information Interchange (ASCII) or Indian Script Code for Information Interchange (ISCII) or Tamil Script Code for Information Interchange (TSCII).

33. Device according to claim 32, characterized in that the result data preferably represent color values ​​and / or brightness values.

34. Device according to one of claims 24 to 33, characterized in that the malware representation data (56) represent a machine-readable character encoding. 35.Device according to claim 34, characterized in that the character encoding is a 2-bit character encoding or at least a 2-bit character encoding or a 3-bit character encoding or a 4-bit character encoding or at least a 4-bit character encoding or a more than 4-bit, in particular 7, 8 or 18-bit character encoding, in particular American Standard Code for Information Interchange (ASCII) or Indian Script Code for Information Interchange (ISCII) or Tamil Script Code for Information Interchange (TSCII).

36. Device according to one of claims 24 to 35, characterized in that the malware representation data (56) represent color values ​​and / or brightness values.

37. Device according to one of claims 1 to 35, characterized in that. the result data can be deleted if the presence of malware or a defined group of malware or a defined probability for the presence of malware can be determined based on the check result.

38. Device according to one of claims 15 to 37, characterized in that the data checking device (46) has a data checking communication interface, wherein the data checking communication interface is connected to the work system (100) or the control device by means of a unidirectional data connection, in particular by means of at least or precisely one optical fiber, for transmitting status data of the data checking device (46). 39.Device according to claim 38, characterized in that the status data preferably comprise the memory utilization, the power utilization, the number of files stored in the data verification device data memory (52) and / or the names of the files stored in the data verification device data memory (52) and / or documentation of executed commands.

40. Device according to one of claims 15 to 39, characterized in that the data verification device (46), in particular at least the data verification logic gate, is part of the data backup and provision device logic gate device, in particular a field programmable gate array (FPGA) or application-specific integrated circuit (ASIC) or complex programmable logic device (CPLD) or simple programmable logic device (SPLD). 41.Device according to one of claims 15 to 40, characterized in that the data checking device (46) is a component of the holding device (28) or the passivation and holding unit (38).

42. Device according to one of claims 2 to 41, characterized in that the reactivation device (80) has at least one data processing device, and wherein the at least one data processing device is configured to convert the digital result data into the digital target data (22).

43. Device according to claim 42, characterized in that the reactivation device (80) has a reactivation device input interface (84) for supplying the result data to the reactivation device (80) and preferably a reactivation device output interface (86) for outputting the target data (22). wherein the reactivation device input interface (84) for forwarding digital signals is preferably connected exclusively via the data processing device to the reactivation device output interface (86).

44. Device according to claim 42 or 43, characterized in that the reactivation device (80) has at least one CPU and / or GPU as the data processing device, and wherein the at least one CPU and / or GPU is configured to convert the digital result data into the digital target data (22).

45. Device according to claim 42 or 43 or 44, characterized in that the target data (22) can be executed and / or analyzed in a sandbox by the data processing device (86) of the reactivation device (80). 46.Device according to one of claims 43 to 45, characterized in that the reactivation device input interface (84) is connected to a data processing device (86, 90, 97) of the reactivation device (80), in particular a reactivation logic gate (90), and / or a reactivation device data memory (96) of the reactivation device (80), wherein the result data can be converted into the target data (22) by the data processing device of the reactivation device (80) and / or analyzed for malware.Device according to claim 46, characterized in that the reactivation device data memory (96) is formed by at least one first reactivation device data memory (92) and one second reactivation device data memory (94), wherein the first reactivation device data memory (92) and the second reactivation device data memory (94) are connected to one another for data purposes exclusively via at least one unidirectionally acting element, in particular the reactivation logic gate.

48. Device according to one of claims 43 to 47, characterized in that the reactivation device (80) has at least one reactivation logic gate (90) as a data processing device, and wherein the at least one reactivation logic gate (90) is configured to convert the digital result data into the digital target data (22).

49. Device according to claim 48, characterized in that the reactivation device input interface (84) for forwarding digital signals is connected to the reactivation device output interface (86) exclusively via the at least one reactivation logic gate (90).

50. Device according to one of claims 47 to 49, characterized in that the first reactivation device data memory (92) for providing the result data is functionally arranged upstream of the reactivation logic gate (90), and the second reactivation device data memory (94) is functionally arranged downstream of the reactivation logic gate (90) for storing the target data (22). 51.Device according to one of claims 46 to 50, characterized in that the reactivation device (80) comprises a CPU and / or GPU (97) or at least one CPU and / or GPU (97) if the data processing device is the at least one reactivation logic gate (90), wherein the CPU and / or GPU is configured to execute and / or analyze the target data (22) in a sandbox (98), in particular to analyze it for malware.

52. Device according to one of claims 46 to 51, characterized in that the reactivation device (80) comprises an update device (85) for updating malware identification data, wherein the CPU and / or GPU (97) is configured to analyze the target data (22) using updated malware identification data. 53.Device according to one of claims 43 to 52, characterized in that the reactivation device (80) has a reactivation device communication interface, wherein the reactivation device communication interface is connected to the work system (100) or the control device by means of a unidirectional data connection, in particular by means of at least or precisely one optical fiber, for transmitting status data of the reactivation device (80).

54. Device according to claim 53, characterized in that. the status data represents at least the memory utilization, the power utilization, and / or the number of files stored in the reactivation device data memory (96), and / or represents the names of the files stored in the reactivation device data memory (96), and / or represents documentation of executed commands.

55. Device according to one of claims 43 to 54, characterized in that the reactivation device (80), in particular at least the reactivation logic gate, is part of the data backup and provision device logic gate device, in particular a field programmable gate array (FPGA), application-specific integrated circuit (ASIC), complex programmable logic device (CPLD), or simple programmable logic device (SPLD). 56.Device according to one of claims 43 to 55, characterized in that the holding device input interface (32) is connected to the reactivation device input interface (84).

57. Device according to one of claims 13 to 56, characterized in that the holding unit output interface (42) of the passivation and holding unit (38) is connected to the reactivation device input interface (84) for transmitting the result data.

58. Device according to claim 57, characterized in that the holding unit output interface (42) of the passivation and holding unit (38) is directly connected to the reactivation device input interface (84). 59.Device according to claim 57, characterized in that the pre-retention unit output interface (42) of the passivation and pre-retention unit (38) is connected directly to the reactivation device input interface (84) via a unidirectional conductor, in particular an optical fiber.

60. Device according to one of claims 7 to 59, characterized in that. the holding device input interface (32) of the holding device (28) is connected to the reactivation device input interface (84) for transmitting the result data.

61. Device according to claim 60, characterized in that the holding device input interface (32) of the holding device (28) is directly connected to the reactivation device input interface (84).

62. Device according to claim 61, characterized in that the holding device input interface (32) of the holding device (28) is directly connected to the reactivation device input interface (84) via a unidirectional conductor, in particular an optical fiber.

63. Device according to one of claims 17 to 62, characterized in that the data checking device output interface (49) of the data checking device (46) is connected to the reactivation device input interface (84) for transmitting the result data. 64.Device according to claim 63, characterized in that the data verification device output interface (49) of the data verification device (46) is directly connected to the reactivation device input interface (84).

65. Device according to claim 64, characterized in that the data verification device output interface (49) of the data verification device (46) is directly connected to the reactivation device input interface (84) via a unidirectional conductor, in particular an optical fiber.

66. Device according to one of claims 4 to 66, characterized in that a pre-emptive device control logic gate part (37) is provided for controlling the pre-emptive device (28). wherein the reserve device control logic gate part (37) is configured to convert original reserve device control data into reserve device control result data.

67. Device according to claim 66, characterized in that a reserve device control data output is provided for outputting the reserve device control result data.

68. Device according to claim 66 or 67, characterized in that the original reserve device control data can be provided by the work system (100) or the control device.

69. Device according to one of claims 1 to 68, characterized in that a reactivation device control logic gate part (78) is provided for controlling the reactivation device (80), wherein the reactivation device control logic gate part (78) is configured to convert original reactivation device control data (77) into reactivation device control result data (79). 70.Device according to claim 69, characterized in that a reactivation device control data output (70) is provided for outputting the reactivation device control result data (79).

71. Device according to claim 69 or 70, characterized in that a reactivation device control data input (72) is provided for supplying the reactivation device control original data (77).

72. Device according to claim 69, 70 or 71, characterized in that the original reactivation device control data (77) can be provided by the work system (100) or the control device (300).

73. Device according to one of claims 15 to 72, characterized in that a data checking device control logic gate part (64) is provided for controlling the data checking device (46), wherein the data checking device control logic gate part (64) is configured to convert original data checking device control data (63) into data checking device control result data (65).

74. Device according to claim 73, characterized in that a data checking device control data output (66) is provided for outputting the data checking device control result data (65).

75. Device according to claim 73 or 74, characterized in that a data checking device control data input (67) is provided for supplying the data checking device control original data (63).

76. Device according to one of claims 73 to 75, characterized inthat the data verification device control source data (63) can be provided by the work system (100) or the control device (300).

77. Device according to one of claims 1 to 76, characterized in that a deactivation device is provided for deactivating the data backup device, in particular the data backup and provision device (1), in particular the passivation device (2), and / or for deactivating data forwarding, in particular from a system on which the digital source data is stored and from which the source data can be supplied to the passivation device, to the data backup device, in particular the data backup and provision device (1), wherein the deactivation device is dependent on status data of the digital source data and / or system status data of the system,on which the digital original data is stored and from which the original data can be fed to the passivation device, the data backup device, in particular the data backup and provision device (1), in particular the passivation device (2), is deactivated.

78. Device according to claim 77, characterized in that the deactivation of the data backup device, in particular the data backup and provision device (1), in particular the passivation device (2), a physical disconnection of a data connection via which the original data can be supplied to the passivation device in a connected state, the setting of an inactive state, wherein in the inactive state the conversion of the digital original data (4) into the digital result data (6) is paused or terminated, or the interruption of a power supply to the passivation device (6) or a physical disconnection of a data connection connected to the passivation device output interface (14), wherein in a connected state the digital result data can be output to another device, in particular the storage device data memory. 79.Device according to claim 77 or 78, characterized in that the inactivation device is part of the system on which the digital original data is stored and from which the original data can be supplied to the passivation device, and / or part of the data backup device, in particular the data backup and provision device (1).

80. Device according to claim 77 or 78 or 79, characterized in that the inactivation device is configured to analyze the system on which the digital original data is stored and from which the original data can be supplied to the passivation device with regard to encryption parameters.

81. Device according to claim 77 or 78 or 79 or 80, characterized in that the inactivation device is configured as an intrusion protection system (IPS) or is connected to an intrusion protection system (IPS) via data and / or signaling. 82.Device according to one of claims 1 to 81, characterized in that the passivation logic gate (8) is configured to generate zero binary sequence representations for zeros of the first binary sequence (16) of the digital original data, and wherein the passivation logic gate (8) is configured to generate one binary sequence representations for ones of the first binary sequence (16) of the digital original data.

83. Device according to claim 82, characterized in that the zero binary sequence representation has at least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits.

84. Device according to claim 82 or 83, characterized in that the one binary sequence representation has at least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits. 85.Device according to one of claims 82 to 84, characterized in that the passivation logic gate is configured to specify, provide, determine, select, or generate different zero binary sequence representations and / or one binary sequence representations for different source data, in particular different files, in particular source data to be processed one after the other.

86. Device according to one of claims 82 to 85, characterized in that, for generating result data, the passivation logic gate is configured to specify, provide, determine, select, or generate different zero binary sequence representations and / or one binary sequence representations for source data of a file, in particular the first binary sequence. 87.Device according to claim 85 or 86, characterized in that the passivation logic gate executes an algorithm for the predetermined setting or generation or determination of the zero binary sequence representations and / or the one binary sequence representations or the passivation logic gate executes a random algorithm for the random setting or generation or determination of the zero binary sequence representations and / or the one binary sequence representations or. one look-up table or multiple look-up tables with a plurality of fixed zero-one binary sequence representation combinations are provided, and the passivation logic gate is configured to select, in particular randomly select, different zero-one binary sequence representation combinations, wherein the one look-up table or the multiple look-up tables have at least 10, in particular at least 100 and preferably at least 1000 and particularly preferably more than 3000 and most preferably more than 5000 or 10000, different zero-one binary sequence representation combinations. 88.Apparatus according to claim 87, characterized in that the one look-up table or the plurality of look-up tables comprise zero-one binary sequence representation combinations, wherein the zero-one binary sequence representation combinations comprise zero bit representations and one bit representations, wherein at least individual zero bit representations of the zero-one binary sequence representation combinations each comprise a first number of bits, and wherein at least individual one bit representations of the zero-one binary sequence representation combinations each comprise a second number of bits, wherein at least for individual zero-one binary sequence representation combinations, the first number of bits and the second number of bits are the same and / or wherein at least for individual zero-one binary sequence representation combinations, the first number of bits and the second number of bits are different. 89.Device according to claim 87 or 88, characterized in that the look-up table or the look-up tables are provided, stored, or deposited in a memory device of the passivation device.

90. Device according to one of claims 82 to 89, characterized in that the passivation logic gate is configured to generate result data with respect to the original data of a file, wherein the result data can be generated with a plurality of mutually different zero binary sequence representations, wherein the mutually different zero binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length.

91. The device according to claim 90, characterized in that the passivation logic gate is configured to generate result data with respect to the source data of a file, wherein the result data can be generated with a plurality of mutually different one-binary sequence representations, wherein the mutually different one-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length. 92.Device according to one of claims 82 to 91, characterized in that the passivation logic gate is configured to generate result data with respect to the original data of a file, wherein the result data can be generated with a plurality of mutually different one-binary sequence representations, wherein the mutually different one-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, and wherein the passivation logic gate is configured to generate the result data with a plurality of mutually different zero-binary sequence representations, wherein the mutually different zero-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, wherein the bit sequences of the result data for the zero-binary sequence representations and the one-binary sequence representations are different from one another. 93.Device according to one of claims 85 to 92, characterized in that the passivation logic gate is configured to generate representative data for the result data or with regard to the result data, the representative data indicating which zero binary sequence representations and / or one binary sequence representations the result data, in particular the respective concrete result data file, have.

94. Device according to claim 93, characterized in that the representative data indicate which zero binary sequence representations and / or which one binary sequence representations the result data form at which position in the result data.

95. Device according to claim 94, characterized in that the representative data identify a first one binary sequence representation with a first bit length in a first number for replacing the first number of ones in the original data and the representative data a second one. Identify binary sequence representations with a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of ones of the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, and wherein the second number of ones of the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, wherein the first number and the second number are different from each other or wherein the first number and the second number are the same.

96. Device according to claim 94 or 95, characterized inthat the representative data identify a first zero binary sequence representation with a first bit length in a first number for replacing the first number of zeros of the original data, and the representative data identify a second zero binary sequence representation with a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of zeros of the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data or preferably up to 10,000 consecutive zeros, and wherein the second number of zeros of the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data or preferably up to 10,000 consecutive zeros,wherein the first number and the second number are different from one another or wherein the first number and the second number are the same.

97. The device according to claim 93, wherein the passivation logic gate is configured to divide the first binary sequence into original data bit sequences, wherein the original data bit sequences have a plurality of bits, wherein the plurality of bits consists of one "0" bit or a plurality of "0" bits and one "1" bit or a plurality of "1" bits or of "0" bits or of "1" bits, and wherein the passivation logic gate is configured to store the bit number of each original data bit sequence in the representative data, and, wherein the passivation logic gate is configured to store, in particular to generate or select, a bit representation combination in the representative data for each original data bit sequence, wherein each bit representation combination has a zero binary sequence representation or a link with a zero binary sequence representation for all "0" bits of an original data bit sequence, and wherein each bit representation combination has a one binary sequence representation or a link with a one binary sequence representation for all "1" bits of the same original data bit sequence, or wherein each bit representation combination has a zero-one binary sequence representation combination or a link with a zero-one binary sequence representation combination for all "0" bits and "1" bits of an original data bit sequence. 98.Device according to claim 97, characterized in that the passivation logic gate is configured to divide the first n bits of the first binary sequence into original data bit sequences whose average number of bits is less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the first n bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than 500 bits and most preferably less than 200 bits, and / or the passivation logic gate is configured to divide the last m bits of the first binary sequence into original data bit sequences whose average number of bits is less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the last m bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than than 500 bits and most preferably less than 200 bits.

99. Device according to claim 98, characterized in that the passivation logic gate is configured to divide the first n bits of the first binary sequence into original data bit sequences whose number of bits lies between 2 bits and 50 bits, in particular between 4 bits and 20 bits and preferably between 5 bits and 15 bits, and / or the passivation logic gate is configured to divide the last m bits of the first binary sequence into original data bit sequences whose number of bits lies between 2 bits and 50 bits, in particular between 4 bits and 20 bits and preferably between 5 bits and 15 bits.

100. Device according to claim 99, characterized in that the passivation logic gate is configured to divide the bits between the first n bits, in particular 100 bits, of the first binary sequence and the last m bits, in particular 100 bits, of the first bit sequence into source data bit sequences whose average number of bits is greater than 20 bits, in particular greater than 50 bits or greater than 100 bits.

101. Device according to claim 99 or 100, characterized in that the number of different zero binary sequence representations and the number of different one binary sequence representations per result data, in particular per result data record or result data file, are the same or different.

102. Device according to claims 93 to 101, characterized in that the representative data 7 can be generated as part of the result data 6. 103.Device according to claims 93 to 101, characterized in that the representation data 7 can be generated as a separate data set assigned to the result data 6.

104. Device according to claim one of claims 82 to 103, characterized in that an analysis unit 170 is provided for determining at least one malware signature or malware signature data, wherein the analysis unit 170 is configured to generate analysis bit representation data 172 and / or a text representation 180 with a processing device 171 on the basis of result data 6, in particular also on the basis of the representation data 7 assigned to or associated with the respective result data 6, wherein the analysis bit representation data 172 represents the first bit sequence 16 in encrypted form and wherein the analysis bit representation data 172 is encrypted with regard to a malware signature or malware signature contained in the first bit sequence 16.Malware signature 503 or with respect to several malicious code signature data or malware signatures 503 or malicious code signatures or malware signatures contained in the first bit sequence 16 and / or. wherein the text representation 180 is analyzable with respect to a malicious code signature or malware signature 503 contained in the first bit sequence 16 or with respect to a plurality of malicious code signature data or malware signatures 503 or malicious code signatures or malware signatures contained in the first bit sequence 16.

105. Device according to claim 104, characterized in that the analysis bit representation data 172 with respect to the zero binary sequence representations 19 of the result data 6, in particular of a result data file, have a plurality of first bit blocks for at least or exactly one zero analysis bit representation 176 of a standardization system, and wherein the analysis bit representation data 172 with respect tothe ones-binary sequence representations 20 of the result data 6, in particular of a result data file, have a plurality of second bit blocks to at least or exactly one ones-analysis bit representation 178 of the standardization system, wherein the standardization system has a plurality of different bit blocks, wherein each bit block is assigned a unique comparison parameter.

106. Apparatus according to claim 104 or 105, characterized in that the analysis unit 170 has a processing device 170, in particular one or at least one logic gate device, such as an ASIC or an FPGA, and / or one or at least one CPU and / or one or at least one GPU, and a processing device 171, in particular a processing editor, in particular a color, grayscale, and / or character editor. 107.Device according to claim 105 or 106, characterized in that the comparison parameter is selected from the following group of comparison parameters 169: symbols, colors, grayscale, tones, and / or patterns.

108. Device according to claim 107, characterized in that the grayscale or colors can be optically output for each bit block by means of at least one pixel or several pixels, in particular 2, 3, 4, 5, or up to 10, or more than 10, or up to 200 pixels.

109. Device according to claim one of claims 105 to 108, characterized in that. 4 or more than 4 or 8 or more than 8 or 16 or more than 16 or 32 or more than 32 or up to 32 or preferably 64 or more than 64 or up to 64 or particularly preferably 128 or more than 128 or up to 128 or most preferably 256 or more than 256 or up to 256 different bit blocks are provided.

110. Device according to claim 107, characterized in that the symbols are embodied as numbers and / or letters and / or characters, in particular numbers and / or letters and / or characters according to ASCII code.

111. Device according to claim 110, characterized in that an assignment of bit blocks and symbols is:

112. Device according to claim 107, characterized in that the colors are 128 different colors or more than 128 different colors or preferably 256 different colors or more than 256 different colors or 512 different colors or more than 512 different colors.

113. Device according to claim 112, characterized in that an assignment of bit blocks and colors is: 0000000 color value 1 0000001 color value 2 ... 0111111 color value 128.

114. Device according to claim 107, characterized in that the gray levels are 128 different gray levels or more than 128 different gray levels or preferably 256 different gray levels or more than 256 different gray levels or 512 different gray levels or more than 512 different gray levels.

115. Device according to claim 114, characterized in that an assignment of bit blocks and gray levels is: 0000000 gray value 1 0000001 gray value 2 ... 0111111 gray value 128. 116.Device according to claim 104, characterized in that the data backup and provision device has a data memory, wherein the analysis unit can effect a data modification and / or data generation on the data memory and / or the deletion of data and / or the retrieval of data from the data memory.

117. Device according to claim 105, characterized in that the passivation device, in particular the passivation logic gate, is configured to randomly predetermine a zero analysis bit representation with respect to the zero binary sequence representations of the first binary sequence, and the. Passivation device, in particular the passivation logic gate, is configured to randomly specify a one-analysis bit representation with respect to the one-binary sequence representations of the first binary sequence.

118. Device according to claim 117, characterized in that the passivation device, in particular the passivation logic gate, is configured to generate the specification of the zero-analysis bit representation and the one-analysis bit representation as part of the result data 6 and / or as part of the representation data 7 and / or as part of the analysis bit representation data.

119. Device according to claim one of claims 104 to 116, characterized in that the analysis unit is configured to generate the analysis bit representation data with respect to.to randomly specify, determine, or select at least one or exactly one zero analysis bit representation from the zero binary sequence representations of the first binary sequence, and the analysis unit is configured to randomly specify, determine, or select at least one or exactly one one analysis bit representation for generating the analysis bit representation data with respect to the one binary sequence representations of the first binary sequence.

120. Device according to claim 116 to 119, characterized in that malware signature data can be retained, in particular stored, in the data memory.

121. Device according to claim 120, characterized in that the malware signature data can be provided as malware signature reference data. 122.The device according to claim 121, characterized in that the analysis unit is configured to generate comparison data for comparison with the analysis bit representation data based on the malware signature reference data.

123. The device according to claim 122, characterized in that. the comparison data can be generated according to the at least one, and preferably exactly one, zero analysis bit representation and according to the at least one, or preferably exactly one, one analysis bit representation.

124. Device according to claim 120, characterized in that the malware signature data can be provided as a malware signature comparison table, wherein the analysis unit is configured to select comparison data from the malware signature comparison table for comparison with the analysis bit representation data.

125. Device according to one of claims 1 to 124, characterized in that the reactivation device (80), in particular a logic gate, in particular an FPGA or ASIC, is configured to effect the conversion of the result data into the target data (22) depending on the representative data or a part of the representative data or inverse representative data or a part of inverse representative data. 126.A control system for controlling at least one digital subsystem via a network, in particular the Internet, wherein the digital subsystem has a data input interface, the data input interface being connected to the network on the one hand and to a control logic gate on the other hand, the control logic gate being configured to generate defined control signals or control data as a function of control source data supplied to the data input interface via the network, the bit sequence of the control source data preferably being different from the bit sequence of the control signals or control data.

127. A control system according to claim 126, characterized in that the digital subsystem is a data backup device, in particular a data backup and provision device (1), according to one of claims 1 to 124. 128.A control system according to claim 127, characterized in that the control logic gate is configured to limit the amount of control signals to a maximum number per unit of time and / or to discard control signals that deviate from defined sequences of control signals.

129. Control system according to claim 127 or 128, characterized in that the digital subsystem has at least one unidirectional data line channel, in particular an optical fiber, for outputting status data.

130. Control system according to claim 127, 128, or 129, characterized in that control data for controlling the subsystem can be supplied to the subsystem exclusively via the control logic gate.

131. Control system according to one of claims 127 to 130, characterized in that the status data can be output to the network exclusively via the unidirectional data line channel.

132. Control system according to one of claims 127 to 130, characterized in that the subsystem is a robot.

133. Control system according to one of claims 127 to 130, characterized in that the subsystem is a router, in particular a network router, in particular an internet router. 134.Control system according to one of claims 127 to 130, characterized in that the subsystem is a vehicle, in particular a car or a truck or an aircraft or a construction vehicle, in particular an excavator or a concrete mixer or a bulldozer, or a helicopter or a boat or a two-wheeler, in particular a motorcycle or scooter or a bicycle, in particular an e-bike, or a rail-bound vehicle, in particular a train.

135. Control system according to one of claims 127 to 130, characterized in that. the subsystem comprises one or more actuators, in particular motor(s), in particular electrically and / or pneumatically and / or hydraulically and / or by means of combustion processes, and / or one or more water supply facilities and / or a factory, in particular for the production of basic chemicals, refinery or waste incineration or food production or drug / vaccine production, or several factories and / or one or more medical devices and / or one or more medical devices and / or one or more communication devices and / or one or more energy supply facilities, in particular a solar power plant, coal-fired power plant, wind power plant, gas-fired power plant, nuclear power plant, hydroelectric power plant or tidal power plant, or several energy supply facilities and / or one or more production devices, in particular an industrial robot, or several production devices.

136. Control system according to one of claims 127 to 134,wherein at least one control data processing processor is provided for generating a plurality of different analog signals of a control representation type depending on digital control source data, wherein the digital control source data represent a plurality of different input commands from at least one input device, wherein the plurality of different input commands of the digital control source data are represented by a plurality of different analog signals of the control representation type, wherein the plurality of different analog signals of the control representation type can preferably be generated in a plurality of, in particular at least four, different states, wherein a plurality of or each analog signal of the control representation type of the plurality of different analog signals of the control representation type represents a defined input command, in particular directly or indirectly,wherein the control data processing processor has at least one data interface for receiving the digital control source data, wherein the control data processing processor has at least one signal output for outputting the analog signals of the control representation type, a control input signal processing processor for converting the analog signals of the control representation type into the digital control result data for manipulating the digital control result data, wherein the control input signal processing processor has at least one signal input for receiving the analog signals of the control representation type output via the at least one signal output of the control data processing processor, wherein the digital control result data is a digital representation of at least a portion of the analog signals of the control representation type,wherein the control input signal processing processor is at least indirectly coupled to a function processor device for executing or effecting at least one function and preferably a plurality of functions.

137. System according to claim 136, characterized in that, the control of the function processor device can be effected to execute at least one defined function and preferably a plurality of different functions depending on the digital control result data.

138. System according to claim 137, characterized in that the digital control result data can be generated for defined analog signals of the control representation type.

139. System according to claim 138, characterized in that the defined analog signals of the control representation type are assigned to the defined function or the defined functions of the function processor device or represent them.

140. System according to one of claims 136 to 138, characterized in that a function output signal processing processor is provided for generating a plurality of different analog signals of the function processing type to represent the control of the function processor device. 141.System according to claim 140, characterized in that the plurality of different analog signals can be generated in at least four mutually different states.

142. System according to one of claims 140 or 141, characterized in that a function data processing processor is provided for generating visualization data for visualizing a function processor control visualization, in particular a function processor control mask.

143. System according to claim 141, characterized in that the function processor control visualization can be generated as a function processor control mask.

144. System according to claim 141 or 142, characterized in that the function processor control visualization can be generated at least partially as a function of the analog signals of the function processing type generated by the function output signal processing processor.

145. System according to claim 143, characterized in that. a manipulation of the function processor control visualization can be effected by the at least one input device.

146. System according to claim 144, characterized in that the digital control source data can be generated as a function of the manipulation of the function processor control visualization.

147. System according to claim 145, characterized in that the function processor control visualization and the control data processing processor are connected to one another at least indirectly via the data interface.

148. System according to one of claims 126 to 145, characterized in that the plurality of different analog signals of the bit-part combination representation type comprises at least four different analog signals of the bit-part combination representation type. 149.System according to claim 148, characterized in that the plurality of different analog signals of the bit-part combination representation type comprises at least thirty-two different analog signals of the bit-part combination representation type.

150. System according to claim 148 or claim 149, characterized in that the control-originating data processor for generating the plurality of different analog signals of the bit-part combination representation type has at least one signal output, wherein the signal output can be supplied with a plurality of different combinations of at least voltage and current.

151. System according to claim 149, characterized in that the different combinations of at least voltage and current are individual analog signals or modulated multiple signals. 152.System according to claim 148, characterized in that the control source data processing processor for generating the plurality of different analog signals of the bit part combination representation type has a plurality of independently controllable signal outputs, wherein at least several signal outputs can each be supplied by the control source data processing processor with a plurality of different combinations of voltage and current.

153. System according to claim 150, characterized in that a plurality of different combinations of voltage and current per signal output comprises at least sixteen combinations.

154. System according to claim 153, characterized in that a plurality of different combinations of voltage and current per signal output comprises at least thirty-two different combinations.

155. System according to claim 153 or 154, characterized in that at least several of the independently controllable signal outputs can be controlled simultaneously to generate an analog signal, or at least several of the independently controllable signal outputs can be controlled simultaneously to generate a modulated analog signal. 156.System according to one of claims 126 to 155, characterized in that the digital control result data has a control result data format and the digital source data has a source data format, wherein the source data format and the control result data format are different.

157. System according to one of claims 126 to 155, characterized in that the input signal processing processor has at least one input signal processing processor output for outputting the digital control result data.

158. System according to claim 157, characterized in that the input signal processing processor output is coupled to a storage medium for digitally storing the digital control result data.

159. System according to claim 158, characterized in that there is preferably no digital data connection for transmitting digital control source data between the storage medium and the control source data processing processor. 160.System according to one of claims 126 to 159, characterized in that the input signal processing processor and the control origin data processing processor are arranged on a board.

161. System according to claim 160, characterized in that the path of the analog signals of the bit-part combination representation type from the control source data processing processor to the input signal processing processor is shorter than 100 cm.

162. System according to claim 161, characterized in that the path (5) of the analog signals of the bit-part combination representation type from the control source data processing processor to the input signal processing processor is shorter than 20 cm.

163. System according to claim 162, characterized in that the path of the analog signals of the bit-part combination representation type from the control source data processing processor to the input signal processing processor is shorter than 50 mm.

164. System according to claim 163, characterized in that the path of the analog signals of the bit-part combination representation type from the control source data processing processor to the input signal processing processor is shorter than 10 mm. 165.System according to claim 163, characterized in that the path of the bit-part combination representation type analog signals from the control source data processing processor to the input signal processing processor is shorter than 5 mm.

166. System according to one of the preceding claims 126 to 165, characterized in that the control source data is source reactivation device control data and / or source data checking device control data and / or source retention device control data.

167. System according to one of the preceding claims 126 to 166, characterized in that the control result data is data checking device control result data and / or retention device control result data and / or reactivation device control result data.

168. Logic gate device for securing data, comprising: at least one passivation logic gate part, wherein the at least one passivation logic gate part is configured to convert digital source data into digital result data, wherein the result data represents a passivated form of the digital source data, wherein the passivation logic gate part is configured to generate one or more zero binary sequence representations for zeros of a first binary sequence (16) of the digital source data, and wherein the passivation logic gate part is configured to generate one or more one binary sequence representations for ones of the first binary sequence (16) of the digital source data, wherein the zero binary sequence representation has at least two bits or the zero binary sequence representations each have at least two bits,and wherein the one-binary sequence representation has at least two bits or wherein the one-binary sequence representations each have at least two bits, and wherein the passivation logic gate part is configured to specify, provide, determine, or generate different combinations of zero-binary sequence representations and one-binary sequence representations for different source data, in particular different files, in particular source data to be processed successively.

169. Logic gate device according to claim 168, characterized in that the passivation logic gate part has a hold-up device data supply output for outputting the result data to a hold-up device (28).

170. Logic gate device according to claim 168 or 169, comprising a hold-up device control logic gate part, wherein the hold-up device control logic gate part is configured,to convert original buffer control data into buffer control result data.

171. A logic gate device according to claim 170, characterized in that the buffer control logic gate part has a buffer control data output for outputting the buffer control result data.

172. The logic gate device according to any one of claims 168 to 171, comprising a reactivation logic gate part, the reactivation logic gate part being configured to convert the result data into target data (22).

173. The logic gate device according to claim 172, characterized in that the hold-up device drive logic gate part or a data verification logic gate part has a reactivation device data supply output for outputting the target data to a reactivation device (80).

174. The logic gate device according to any one of claims 169 to 173, characterized in that the reactivation logic gate part has a reactivation device data supply input for supplying the result data. 175.Logic gate device according to claims 172 to 174, characterized in that a reactivation device control logic gate part for controlling the reactivation device (80), wherein the reactivation device control logic gate part is configured to convert original reactivation device control data into reactivation device control result data.

176. Logic gate device according to claim 175, characterized in that a reactivation device control data output is provided for outputting the reactivation device control result data.

177. Logic gate device according to claim 175 or 176, characterized in that a reactivation device control data input is provided for supplying the reactivation device control original data.

178. Logic gate device according to one of claims 168 to 177. characterized in that at least one data verification logic gate part is provided, wherein the at least one data verification logic gate (60) is configured to analyze digital result data (6) for malware.

179. Logic gate device according to claim 178, characterized in that a data verification logic gate part compares representation information, in particular binary sequences or parts of the binary sequences of the malware, of malware held in a lookup table (62) with the binary sequence or parts of the binary sequence of the original data or performs a comparison according to a defined execution logic, in particular an algorithm. 180.Logic gate device according to claim 178 or 179, characterized in that the data verification logic gate part is configured to convert the result data into the original data in a first step and then to effect the comparison with the representation information stored in the lookup table (62).

181. Logic gate device according to claim 178 or 179 or 180, characterized in that a data verification logic gate part output or each data verification logic gate part output via which the original data generated from the result data can be output to an original data memory and / or the original data memory is physically separated from the storage device data memory (30) and / or the reactivation device data memory (96), in particular such that malware cannot reach the storage device data memory (30) and / or the reactivation device data memory (96). 182.Logic gate device according to claim 178 or 179 or 180 or 181, characterized in that the original data generated by the data verification logic gate part are deleted after the comparison, and preferably the memory area in which the data was provided is formatted.

183. Logic gate device according to one of claims 179 to 182, characterized in that comparison data are generated depending on the comparison result, wherein the comparison data correspond to the data stored in the storage device (28). Result data are assigned or the corresponding result data are supplemented by the comparison data.

184. Logic gate device according to one of claims 179 to 183, characterized in that the comparison data comprise information on the version of the representation information and / or the comparison result.

185. Logic gate device according to one of claims 179 to 184, characterized in that the data verification logic gate part compares binary sequences of malware result data stored in a lookup table (62) with the binary sequence of the result data.

186. Logic gate device according to one of claims 179 to 185, characterized in that the binary sequences of the malware result data stored in the lookup table (62) are generated from malware original data in accordance with the conversion of the original data into the result data. 187.A logic gate device according to any one of claims 179 to 186, comprising a data verification device control logic gate part for controlling the data verification device (46), wherein the data verification device control logic gate part is configured to convert original data verification device control data into data verification device control result data.

188. A logic gate device according to claim 187, characterized in that a data verification device control data output is provided for outputting the data verification device control result data.

189. A logic gate device according to claim 187 or 188, characterized in that a data verification device control data input is provided for supplying the data verification device control original data.

190. Logic gate device according to one of the preceding claims 168 to 189, characterized in that one or more FPGAs are provided.

191. Logic gate device according to one of the preceding claims 168 to 190, characterized in that at least two or exactly two or at least three or exactly three or at least four or exactly four of the logic gates: passivation logic gate part, retention device control logic gate part, reactivation logic gate part, reactivation device control logic gate part, data verification logic gate part, and / or data verification device control logic gate part are formed by an FPGA. 192.Logic gate device according to one of the preceding claims 168 to 191, characterized in that at least two or exactly two or at least three or exactly three or at least four or exactly four of the logic gates: passivation logic gate part, reserve device control logic gate part, reactivation logic gate part, reactivation device control logic gate part, data verification logic gate part and / or data verification device control logic gate part are each formed by an FPGA. 193.Logic gate device according to one of the preceding claims 168 to 192, characterized in that at least two or exactly two or at least three or exactly three or at least four or exactly four of the logic gates: passivation logic gate part, reserve device control logic gate part, reactivation logic gate part, reactivation device control logic gate part, data verification logic gate part and / or data verification device control logic gate part are each formed by a plurality of FPGAs.

194. Device according to one of claims 168 to 193, characterized in that the passivation logic gate part is configured to specify or provide or determine or generate different zero binary sequence representations and / or one binary sequence representations, in particular different combinations of zero binary sequence representations and / or one binary sequence representations, for source data of a file.

195. Device according to one of claims 168 to 194, characterized in that the passivation logic gate part executes an algorithm for the predetermined setting or generation or determination of the zero binary sequence representations and / or the one binary sequence representations or the passivation logic gate part executes a random algorithm for the random setting or generation or determination of the zero binary sequence representations and / or the one binary sequence representations or one or more look-up tables with a plurality of fixed zero-one binary sequence representation combinations are provided and the passivation logic gate part is configured to select different zero-one binary sequence representation combinations, in particular to select them randomly, wherein the one look-up table or the plurality of look-up tables have at least 10,in particular at least 100, and preferably at least 1000, and particularly preferably more than 3000, and most preferably more than 5000 or 10000, different zero-one binary sequence representation combinations.

196. Device according to claim 195, characterized in that the passivation logic gate part is configured to generate result data with respect to the original data of a file, wherein the result data can be generated with a plurality of mutually different zero binary sequence representations, wherein the mutually different zero binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length.

197. Device according to claim 195 or 196, characterized in that the passivation logic gate part is configured to generate result data with respect to the original data of a file,wherein the result data can be generated with a plurality of mutually different one-binary sequence representations, wherein the mutually different one-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length.

198. Apparatus according to claim 197, characterized in that the passivation logic gate part is configured to generate result data with respect to the original data of a file, wherein the result data can be generated with a plurality of mutually different one-binary sequence representations, wherein the mutually different one-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, and wherein the passivation logic gate part is configured to generate the result data with a plurality of mutually different zero-binary sequence representations,where the different zero binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, wherein the bit sequences of the result data for the zero binary sequence representations and the one binary sequence representations are different from one another.

199. Device according to one of claims 174 to 198, characterized in that the passivation logic gate part is configured to generate representative data for the result data, wherein the representative data indicates which zero binary sequence representations and / or one binary sequence representations the result data, in particular the respective concrete result data file, has.

200. Device according to claim 199, characterized in that the representative data indicates which zero binary sequence representations and / or which one binary sequence representations form the result data at which position in the result data.

201. Device according to claim 200, characterized inthat the representative data identify a first one-binary sequence representation with a first bit length in a first number for replacing the first number of ones of the original data, and the representative data identify a second one-binary sequence representation with a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of ones of the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, and wherein the second number of ones of the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones,wherein the first number and the second number are different from each other or wherein the first number and the second number are the same.

202. Apparatus according to claim 200 or 201, characterized in that the representative data identify a first zero binary sequence representation with a first bit length in a first number for replacing the first number of zeros of the original data and the representative data a second zero, Identify binary sequence representations having a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of zeros of the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data, or preferably up to 10,000 consecutive zeros, and wherein the second number of zeros of the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data, or preferably up to 10,000 consecutive zeros, wherein the first number and the second number are different from one another or wherein the first number and the second number are the same. 203.Device according to claim 201 or 202, characterized in that the number of different zero binary sequence representations and the number of different one binary sequence representations per result data, in particular per result data record or result data file, is the same or different.

204. Device according to claims 199 to 203, characterized in that the representative data can be generated as part of the result data.

205. Device according to claims 199 to 204, characterized in that the representative data can be generated as a separate data record assigned to the result data.

206. Device according to claim 204 or 205, characterized in that the reactivation device (80), in particular a logic gate, in particular an FPGA or ASIC, is configured to effect the conversion of the result data into the target data (22) depending on the representative data. 207.System according to one of the preceding claims 126 to 167, characterized in that the function processor device is the data checking device and / or holding device and / or the reactivation device and / or the logic gate device, in particular according to one of claims 168 to 206.

208. A method for data backup, comprising at least the steps of: converting digital source data (4) into digital result data (6) by means of a passivation device, wherein the passivation device has at least one passivation logic gate (8), and wherein the at least one passivation logic gate (8) is configured to convert the digital source data (4) into the digital result data and to generate the result data, wherein the passivation device (2) has a passivation device input interface (10) for supplying the source data to the at least one passivation logic gate (8), and wherein the passivation device (2) has a passivation device output interface (14) for outputting the result data generated by the at least one passivation logic gate (8), wherein the digital source data (4) is defined by a first binary sequence (16),wherein the digital result data are defined by a second binary sequence (18), wherein the first binary sequence (16) and the second binary sequence (18) are different from one another, converting the result data into target data (22) by means of a reactivation device (80), wherein the reactivation device (80) has a reactivation device input interface (84) for supplying the result data to the reactivation device (80) and preferably a reactivation device output interface (86) for outputting the target data (22), wherein the target data (22) preferably correspond to the original data by at least 90% or at least 95% or at least 99% or at least 99.9% or exactly 100%.

209. Method according to claim 208, characterized in that the passivation logic gate (8) is configured to generate zero binary sequence representations for zeros of the first binary sequence (16) of the original digital data,and wherein the passivation logic gate (8) is configured to generate one-bit binary sequence representations for ones of the first binary sequence (16) of the digital original data.

210. The method according to claim 209, characterized in that the zero-bit binary sequence representation comprises at least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits.

211. Method according to claim 210, characterized in that the one-binary sequence representation has at least two bits and preferably more than 2 bits, in particular 3 bits or more than 3 bits or 4 bits or more than 4 bits or 5 bits or more than 5 bits or 6 bits or more than 6 bits or 7 bits or more than 7 bits or 8 bits or more than 8 bits.

212. Method according to claim 211, characterized in that the passivation logic gate is configured to specify, provide, determine, or generate different zero-binary sequence representations and / or one-binary sequence representations for different source data, in particular different files, in particular source data to be processed successively. 213.Method according to claim 212, characterized in that, for generating result data, the passivation logic gate is configured to specify, provide, determine, or generate different zero binary sequence representations and / or one binary sequence representations for the original data of a file, in particular the first binary sequence. 214.Method according to claim 212 or 213, characterized in that the passivation logic gate executes an algorithm for the predetermined definition or generation or determination of the zero binary sequence representations and / or the one binary sequence representations or the passivation logic gate executes a random algorithm for the random definition or generation or determination of the zero binary sequence representations and / or the one binary sequence representations or a look-up table or a plurality of look-up tables with a plurality of defined zero-one binary sequence representation combinations are provided and the passivation logic gate is configured to select, in particular randomly select, different zero-one binary sequence representation combinations, wherein the one look-up table or the plurality of look-up tables have at least 10, in particular at least 100 and preferably at least 1000 and particularly preferably more. than 3000, and most preferably more than 5000 or 10000, different zero-one binary sequence representation combinations. 215.Method according to claim 214, characterized in that the one look-up table or the plurality of look-up tables comprise zero-one binary sequence representation combinations, wherein the zero-one binary sequence representation combinations comprise zero bit representations and one bit representations, wherein at least individual zero bit representations of the zero-one binary sequence representation combinations each comprise a first number of bits, and wherein at least individual one bit representations of the zero-one binary sequence representation combinations each comprise a second number of bits, wherein at least for individual zero-one binary sequence representation combinations, the first number of bits and the second number of bits are the same and / or wherein at least for individual zero-one binary sequence representation combinations, the first number of bits and the second number of bits are different. 216.Method according to claim 214 or 215, characterized in that the look-up table or the look-up tables are provided, stored, or deposited in a memory device of the passivation device.

217. Method according to one of claims 208 to 216, characterized in that the passivation logic gate is configured to generate result data with respect to the original data of a file, wherein the result data are generated with a plurality of mutually different zero binary sequence representations, wherein the mutually different zero binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length.

218. Method according to one of claims 208 to 217, characterized in that. the passivation logic gate is configured to generate result data with respect to the source data of a file, wherein the result data is generated with a plurality of mutually different one-binary sequence representations, wherein the mutually different one-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length. 219.Method according to one of claims 208 to 218, characterized in that the passivation logic gate is configured to generate result data with respect to the original data of a file, wherein the result data is generated with a plurality of mutually different one-binary sequence representations, wherein the mutually different one-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, and wherein the passivation logic gate is configured to generate the result data with a plurality of mutually different zero-binary sequence representations, wherein the mutually different zero-binary sequence representations have bit sequences of different lengths and / or different bit sequences of the same length, wherein the bit sequences of the result data for the zero-binary sequence representations and the one-binary sequence representations are different from one another. 220.Method according to one of claims 208 to 219, characterized in that the passivation logic gate is configured to generate representative data for the result data or with respect to the result data, wherein the representative data indicates which zero binary sequence representations and / or one binary sequence representations the result data, in particular the respective concrete result data file, comprise.

221. Method according to one of claims 208 to 220, characterized in that the representative data indicates which zero binary sequence representations and / or which one binary sequence representations form the result data at which position in the result data. 222.Method according to one of claims 208 to 221, characterized in that the representative data identify a first ones binary sequence representation with a first bit length in a first number for replacing the first number of ones of the original data and the representative data identify a second ones binary sequence representation with a second bit length in a second number for replacing the second number of ones of the original data. wherein the first number of ones of the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, and wherein the second number of ones of the original data comprises more than two consecutive ones or more than 10 consecutive ones or more than 100 consecutive ones of the original data or preferably up to 10,000 consecutive ones, wherein the first number and the second number are different from one another or wherein the first number and the second number are the same.

223. Method according to one of claims 208 to 216, characterized in thatthat the representative data identify a first zero binary sequence representation with a first bit length in a first number for replacing the first number of zeros of the original data, and the representative data identify a second zero binary sequence representation with a second bit length in a second number for replacing the second number of ones of the original data, wherein the first number of zeros of the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data or preferably up to 10,000 consecutive zeros, and wherein the second number of zeros of the original data comprises more than two consecutive zeros or more than 10 consecutive zeros or more than 100 consecutive zeros of the original data or preferably up to 10,000 consecutive zeros,wherein the first number and the second number are different from one another or wherein the first number and the second number are the same.

224. The method according to any one of claims 208 to 223, characterized in that the passivation logic gate is configured to divide the first binary sequence into original data bit sequences, wherein the original data bit sequences have a plurality of bits, wherein the plurality of bits consist of one "0" bit or a plurality of "0" bits and of one "1" bit or a plurality of "1" bits or of "0" bits or of "1" bits, and wherein the passivation logic gate is configured to store the bit number of each original data bit sequence in the representative data, and wherein the passivation logic gate is configured to store, in particular to generate or select, a bit representation combination for each original data bit sequence in the representative data, wherein each bit representation combination has a zero binary sequence representation or a link with a zero binary sequence representation for all "0" bits of an original data bit sequence, and wherein each bit representation combination has a one binary sequence representation or a link with a one binary sequence representation for all "1" bits of the same original data bit sequence, or wherein each bit representation combination has a zero-one binary sequence representation combination or a link with a zero-one binary sequence representation combination for all "0" and "1" bits of an original data bit sequence. 225.Method according to claim 224, characterized in that the passivation logic gate is configured to divide the first n bits of the first binary sequence into original data bit sequences whose average number of bits is less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the first n bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than 500 bits and most preferably less than 200 bits, and / or the passivation logic gate is configured to divide the last m bits of the first binary sequence into original data bit sequences whose average number of bits is less than 50 bits, in particular less than 20 bits or less than 15 bits, wherein the last m bits are less than 10,000 bits, in particular less than 5,000 bits and preferably less than 1,000 bits and particularly preferably less than 500 bits and most preferably less than 200 bits.

226. Method according to claim 225, characterized in that the passivation logic gate is configured to divide the first n bits of the first binary sequence into original data bit sequences whose number of bits lies between 2 bits and 50 bits, in particular between 4 bits and 20 bits and preferably between 5 bits and 15 bits, and / or the passivation logic gate is configured to divide the last m bits of the first binary sequence into original data bit sequences whose number of bits lies between 2 bits and 50 bits, in particular between 4 bits and 20 bits and preferably between 5 bits and 15 bits.

227. Method according to claim 226, characterized in that. the passivation logic gate is configured to divide the bits between the first n bits, in particular 100 bits, of the first binary sequence and the last m bits, in particular 100 bits, of the first bit sequence into original data bit sequences whose average number of bits is greater than 20 bits, in particular greater than 50 bits or greater than 100 bits.

228. Method according to claim 226 or 227, characterized in that the number of different zero binary sequence representations and the number of different one binary sequence representations per result data, in particular per result data record or result data file, are the same or different.

229. Method according to one of claims 220 to 228, characterized in that the representative data are generated as part of the result data.

230. Method according to one of claims 220 to 228, characterized in that the representative data are generated as a separate data set associated with the result data. 231.Method according to one of claims 208 to 230, characterized in that an analysis unit is provided for determining malware signature data. The analysis unit is configured to generate analysis bit representation data on the basis of result data, in particular also on the basis of the representation data assigned to or associated with the respective result data, wherein the analysis bit representation data represents the first bit sequence in encrypted form and wherein the analysis bit representation data is analyzed with regard to a malicious code signature contained in the first bit sequence or with regard to a plurality of malware signature data contained in the first bit sequence.

232. Method according to claim 231, characterized in that the analysis bit representation data with regard tothe zero binary sequence representations of the result data, in particular of a result data file, have a plurality of first bit blocks to at least or exactly one zero analysis bit representation of a standardization system and. wherein the analysis bit representation data with respect to the ones-binary sequence representations of the result data, in particular of a result data file, comprise a plurality of second bit blocks for at least or exactly one ones-analysis bit representation of the standardization system.

233. Method according to claim 232, characterized in that the standardization system comprises a plurality of different bit blocks, each bit block being assigned a unique comparison parameter.

234. Method according to claim 233, characterized in that the comparison parameter is selected from the following group of comparison parameters: symbols, colors, grayscale, tones, and / or patterns.

235. Method according to claim 234, characterized in that the grayscale or colors per bit block can be optically output by means of at least one pixel or several pixels, in particular 2, 3, 4, 5, or up to 10, or more than 10, or up to 200 pixels. 236.Method according to claim 234 or 235, characterized in that 4 or more than 4 or 8 or more than 8 or 16 or more than 16 or 32 or more than 32 or up to 32 or preferably 64 or more than 64 or up to 64 or particularly preferably 128 or more than 128 or up to 128 or most preferably 256 or more than 256 or up to 256 different bit blocks are provided.

237. Method according to claim 234, characterized in that the symbols are embodied as numbers and / or letters and / or characters, in particular numbers and / or letters and / or characters according to ASCII code.

238. Method according to claim 237, characterized in that. an assignment of bit blocks and symbols is:

239. Method according to claim 234, characterized in that the colors are 128 different colors or more than 128 different colors or preferably 256 different colors or more than 256 different colors or 512 different colors or more than 512 different colors.

240. Method according to claim 239, characterized in that an assignment of bit blocks and colors is: 0000000 color value 1 0000001 color value 2 ... 0111111 color value 128.

241. Method according to claim 234, characterized in that the gray levels are 128 different gray levels or more than 128 different gray levels or preferably 256 different gray levels or more than 256 different gray levels or 512 different gray levels or more than 512 different gray levels.

242. Method according to claim 241, characterized in that an assignment of bit blocks and gray levels is: 0000000 gray value 1 0000001 gray value 2 ... 0111111 gray value 128.

243. Method according to one of claims 208 to 242, characterized in that the data backup and provision device has a data memory, wherein the analysis unit causes data modification and / or data generation on the data memory and / or the deletion of data and / or the retrieval of data from the data memory. 244.Method according to one of claims 208 to 243, characterized in that the passivation device, in particular the passivation logic gate, is configured to randomly predetermine a zero analysis bit representation with respect to the zero binary sequence representations of the first binary sequence, and the passivation device, in particular the passivation logic gate, is configured to randomly predetermine a one analysis bit representation with respect to the one binary sequence representations of the first binary sequence.

245. Method according to claim 244, characterized in that the passivation device, in particular the passivation logic gate, is configured to generate the predetermination of the zero analysis bit representation and the one analysis bit representation as part of the result data and / or as part of the representation data and / or as part of the analysis bit representation data.

246. Method according to one of claims 231 to 245. characterized in that the analysis unit is configured to randomly specify, determine, or select at least one or exactly one zero analysis bit representation for generating the analysis bit representation data with respect to the zero binary sequence representations of the first binary sequence, and the analysis unit is configured to randomly specify, determine, or select at least one or exactly one one analysis bit representation for generating the analysis bit representation data with respect to the one binary sequence representations of the first binary sequence.

247. Method according to one of claims 243 to 246, characterized in that malware signature data is retained, in particular stored, in the data memory.

248. Method according to claim 247, characterized in that the malware signature data is provided as malware signature reference data. 249.Method according to claim 248, characterized in that the analysis unit is configured to use the malware signature reference data or malware reference signature to generate comparison data for comparison with the analysis bit representation data 172 and / or with the text representation 180 of the bits of the digital original data 4.

250. Method according to claim 249, characterized in that the comparison data are generated according to the at least one, and preferably exactly one, zero analysis bit representation and according to the at least one, or preferably exactly one, one analysis bit representation.

251. Method according to claim 250, characterized in that the malware signature data or malware signature is provided as a malware signature comparison table, wherein the analysis unit is configured to select comparison data from the malware signature comparison table for comparison with the analysis bit representation data.

252. Method according to one of claims 208 to 251, characterized in that the reactivation device (80), in particular a logic gate, in particular an FPGA or ASIC, is configured to effect the conversion of the result data into the target data (22) as a function of the representative data or a part of the representative data or inverse representative data or a part of inverse representative data.