A method for software bidding settlement review
By introducing functional review, function point code decomposition, compliance, security and economic review modules in software bidding and settlement review, the problem of lack of comprehensive analysis of open source code in the existing technology is solved, and the software's compliance, security and economic value is effectively evaluated, which reduces development costs and avoids the risk of intellectual property infringement.
Patent Information
- Application Number
- CN202111451449.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-01
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-12-01
AI Technical Summary
The existing software bidding and settlement review lacks a comprehensive analysis of open source code, resulting in low security, false reporting of development volume and high risk of intellectual property infringement.
A method for software bidding and settlement review is proposed, including functional review module, functional point code decomposition module, compliance module, security module, economic review module and open source code management module. Through these modules, comprehensive analysis can be carried out to review the compliance, security and economic value of the software.
Through this method, the compliance and security of the software can be effectively evaluated, the security and intellectual property infringement risks brought by source code can be avoided, the development costs can be reduced, and the code development costs can be formulated.
Smart Images

Figure CN114240337B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of page bidding, and specifically provides a method for software bidding settlement review. Background Art
[0002] Bidding settlement refers to an economic document in which the winning bidder settles the project price with the bidder according to the contract and the completed software project volume. The software development cycle is long and the funds consumed are large. To compensate the winning bidder for the funds consumed in software development in a timely manner, it is necessary to handle an economic document for settling the project price with the bidder based on the software project volume. There are various settlement methods, such as intermediate settlement (progress payment settlement), year-end settlement, and final settlement should be carried out after the completion acceptance of all projects. Bidding settlement is a very important task in bidding.
[0003] At present, the settlement review of bidding mainly focuses on functional and economic reviews. That is, technical experts are responsible for reviewing whether all function points in the bidding list are fully implemented, and financial experts are responsible for reviewing financial expenses.
[0004] However, the software industry is different from traditional engineering construction. Software requires the operation and implementation of hundreds of thousands or even tens of millions of lines of code. In the current software development projects, there are a large number of cases of open-source code being cited. Only conducting functional reviews and economic reviews dominated by experts' experience will lead to the following problems:
[0005] 1. Security: In the era when open-source code is readily available, software developers rely too much on open-source software, but their recognition of the security of open-source software is very low, resulting in a particularly low security level for software development in the entire industry.
[0006] False reporting of development volume; there is no standard to measure the actual manual development volume of software. Especially in the era when open-source code is readily available, it is claimed that open-source code is the code developed by oneself, and the development volume is falsely reported to conceal the actual development value of the software.
[0007] 2. High risk of intellectual property infringement:
[0008] Currently, in the era of coexistence of open-source and closed-source systems, there are also many restrictive usage regulations for open-source software. The definition of intellectual property rights of open-source code is vague, and it is difficult for the tenderer to identify the risks. Therefore, the present invention adds compliance review and security review on the basis of the current review, and thus provides a method for software bidding settlement review. Summary of the Invention
[0009] The purpose of the present invention is to provide a method for software bidding settlement review to solve the problem that there is no technical solution in the prior art that comprehensively analyzes the compliance, security, and economy of software in combination with open-source code.
[0010] To solve the above technical problems, the present invention is achieved through the following technical solutions:
[0011] A method for software bidding settlement review of the present invention includes a function review module, a function point code decomposition module, a compliance module, a security module, an economic review module, and an open source code management module;
[0012] The function point code decomposition module; by combining the tender list, the settlement report (provided by the winning bidder), and the software data dictionary, the entire code is decomposed to generate the code corresponding to the function points;
[0013] The open source code management module is used to improve the open source code database;
[0014] The soft compliance module is used to determine whether the development of the development code corresponding to the software function points complies with the regulations and whether there is intellectual property infringement;
[0015] The security review is used to determine whether there are vulnerabilities in the development of the development code corresponding to the software function points and simultaneously calculate the value required to repair the vulnerabilities;
[0016] The economic review module automatically calculates the economic value of the software code for each function point.
[0017] Preferably: The steps are as follows;
[0018] Step S1, establish a perfect open source code database;
[0019] Step S2, review the project settlement, including reviewing the actual function points and the project source code review;
[0020] Review the actual function points: Determine the total man-hours of development through the project development requirements;
[0021] Project source code review, by comparing with the open source code database in step 1, so as to determine the quantity and proportion of self-developed code and open source code;
[0022] Step S3, conduct an economic review on the above self-developed code and open source code;
[0023] Step S4, obtain the valuable code volume through step S3, and multiply the valuable code volume by the unit price of the function point code to form the final settlement value.
[0024] Preferably: The economic review includes a compliance review and a security review, and the specific steps are as follows,
[0025] Step K1. Determine whether the software code is in the open source code library,
[0026] Step K2. If not, this code is self-developed code and has value,
[0027] Step K3. If it is in the open-source code library, whether this code has obtained the corresponding authorization. If not, this functional point has no economic value.
[0028] Step K4. If it is in the open-source code library and this code has obtained the corresponding authorization, measure the amount of open-source code development.
[0029] Step K5. If it is in the open-source code library and this code has obtained the corresponding authorization, conduct security vulnerability detection.
[0030] Step K6. If vulnerabilities exist, generally this code has no value.
[0031] Step K7. If vulnerabilities exist, in special cases (if the tenderer is in a hurry to use the software), when vulnerabilities exist, measure the cost required to repair the vulnerabilities, and this cost needs to be subtracted during settlement.
[0032] Preferably, the calculation formula for the settlement value of the development code corresponding to the functional point is as follows.
[0033] For functional point 1, the amount of development is A, the amount of self-developed code development is B, the amount of open-source code development with intellectual property compliance is C, and the value required to repair the vulnerabilities of the open-source code with existing vulnerabilities and security compliance is D.
[0034] Then 1) If A = B + C, its economic value is equal to (A - C) * P - D;
[0035] 2) If A < B + C, its economic value is equal to B * P - D;
[0036] 3) If A > B + C, its economic value is equal to (A - C) * P - D;
[0037] 4) If open-source code cannot be used, then A = B, and its economic value is equal to A * P - D;
[0038] 5) If open-source code is used and the code is infringing, its value is 0.
[0039] Preferably, the automatically developed code is defaulted to meet compliance and security.
[0040] Compared with the prior art, the beneficial effects of the present invention are:
[0041] The method for software tendering and bidding settlement review of the present invention complies with the citation of open-source code, utilizes standard development functional points, saves the development cycle and development cost, greatly saves social resources, makes the cost formula of code development, and at the same time avoids security and intellectual property infringement disputes brought by open-source code. Description of the Drawings
[0042] Figure 1 Schematic diagram of the method flow for software bidding settlement review of the present invention;
[0043] Figure 2 Schematic diagram of the economic review module of the present invention. Specific implementation manners
[0044] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0045] Please refer to Figure 1-2 , the figure shows a method for software bidding settlement review of the present invention, including a function review module, a function point code decomposition module, a compliance module, a security module, an economic review module, and an open source code management module;
[0046] The function point code decomposition module; by combining the tender list, the settlement report (provided by the winning bidder), and the software data dictionary, the entire code is decomposed to generate the code corresponding to the function points;
[0047] The open source code management module is used to improve the open source code database;
[0048] The soft compliance module is used to judge whether the development of the development code corresponding to the software function points complies with the regulations and whether there is intellectual property infringement;
[0049] The security review is used to judge whether there are vulnerabilities in the development of the development code corresponding to the software function points, and at the same time measure the value required to repair the vulnerabilities;
[0050] The economic review module automatically calculates the economic value of the software code for each function point.
[0051] The steps are as follows;
[0052] Step S1, establish a perfect open source code database, which is used to compare whether the function points obtained by splitting the code provided by the supplier can be directly obtained from the code source without development.
[0053] Step S2, review the project settlement, including reviewing the actual function points and the project source code review;
[0054] First, review the actual function points: according to the project development requirements, decompose the software requirements in the project development requirements into several function points to be implemented, and estimate the total man-hours of development by multiplying the number of function points by time;
[0055] Project source code review, by comparing with the open-source code database in Step 1, to determine the quantity and proportion of self-developed code and open-source code; among them, the self-developed code is defaulted to be compliant and secure, that is, there is no intellectual property infringement and security vulnerability.
[0056] Step S3. Conduct an economic review on the above self-developed code and open-source code; the review method is as follows.
[0057] Step K1. Determine whether the software code is in the open-source code library.
[0058] Step K2. If not, this code is self-developed code and has value.
[0059] Step K3. If it is in the open-source code library, whether this code has obtained the corresponding authorization. If not, this functional point has no economic value.
[0060] Step K4. If it is in the open-source code library and this code has obtained the corresponding authorization, measure the development volume of the open-source code.
[0061] Step K5. If it is in the open-source code library and this code has obtained the corresponding authorization, conduct security vulnerability detection.
[0062] Step K6. If vulnerabilities exist, generally this code has no value.
[0063] Step K7. If vulnerabilities exist, in special cases (if the tenderer is in a hurry to use the software), when vulnerabilities exist, measure the cost required to repair the vulnerabilities, and this cost needs to be subtracted during settlement.
[0064] Step S4. Obtain the valuable code volume through Step S3, and multiply the valuable code volume by the unit price of the functional point code to form the final settlement value.
[0065] The calculation formula for the settlement value of the development code corresponding to the functional point is as follows.
[0066] The development volume corresponding to Functional Point 1 is A, the self-developed code development volume is B, the development volume of the open-source code with intellectual property compliance is C, the value required to repair the vulnerabilities of the open-source code with existing vulnerabilities and security compliance is D, and P is the development unit price.
[0067] If A = B + C, then its economic value is equal to (A - C) * P - D; if A < B + C, then its economic value is equal to B * P - D; if A > B + C, then its economic value is equal to (A - C) * P - D; if the open-source code cannot be used, then A = B, and its economic value is equal to A * P - D; if the open-source code is used and there is code infringement, then its value is 0.
[0068] The above content is a further detailed description of the present invention in combination with specific embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as falling within the protection scope determined by the claims submitted for the present invention.
Claims
1. A method for software bidding settlement review, characterized in that, it includes a function review module, a function point code decomposition module, a compliance module, a security module, an economic review module, and an open source code management module; The function point code decomposition module decomposes the entire code by combining the bidding list, the settlement report, and the software data dictionary to generate the code corresponding to the function points; The open source code management module is used to improve the open source code database; The compliance module is used to determine whether the development of the development code corresponding to the software function points complies with the regulations and whether there is intellectual property infringement; The security module is used to determine whether there are vulnerabilities in the development of the development code corresponding to the software function points and simultaneously calculate the value required to repair the vulnerabilities; The economic review module automatically calculates the economic value of the software code for each function point; The specific steps of the settlement review are as follows; Step S1. Establish a complete open source code database; Step S2. Review the project settlement, including reviewing the actual function points and the project source code; Review the actual function points: Determine the total man-hours of development according to the project development requirements; For the project source code review, determine the quantity and proportion of the self-developed code and the open source code by comparing with the open source code database in Step S1; Step S3. Conduct an economic review of the above self-developed code and open source code; the economic review includes a compliance review and a security review; Step S4. Obtain the valuable code quantity through Step S3, and multiply the valuable code quantity by the unit price of the function point code to form the final settlement value.
2. A method for software bidding settlement review according to claim 1, characterized in that: The economic review includes a compliance review and a security review, and the specific steps are as follows, Step K1. Determine whether the software code is in the open source code library, Step K2. If not, this code is self-developed code and has value, Step K3. If it is in the open source code library, whether this code has obtained the corresponding authorization. If not, this function point has no economic value, Step K4. If it is in the open source code library and this code has obtained the corresponding authorization, measure its open source code development quantity, Step K5. If it is in the open source code library and this code has obtained the corresponding authorization, conduct a security vulnerability detection, Step K6. If there are vulnerabilities, this code has no value, Step K7. If there are vulnerabilities, measure the cost required to repair the vulnerabilities, and this cost needs to be subtracted during settlement.
3. A method for software bidding settlement review according to claim 2, characterized in that: The calculation formula for the settlement value of the development code corresponding to the function point is as follows, The development quantity corresponding to function point 1 is A, the self-developed code development quantity is B, the open source code intellectual property compliant code development quantity is C, the value required to repair the vulnerabilities of the open source code with vulnerabilities and security compliance is D, and P is the development unit price. Then 1) If A = B + C, its economic value is equal to (A - C) * P - D; 2) If A < B + C, its economic value is equal to B * P - D; 3) If A > B + C, its economic value is equal to (A - C) * P - D; 4) If the open-source code cannot be used, then A = B, and its economic value is equal to A * P - D; If the open-source code is used and there is code infringement, its value is 0.
Citation Information
Patent Citations
Software source code online detection system and method
CN106095446A
Software product autonomous controllability assessment method
CN107766246A
Cited By
Code mapping function point-based automatic accounting and completion settlement method and system, and medium
CN121146812A