A delivery access check method and device, electronic equipment, and storage medium

By performing fully automated checks on the delivery documents, security test results, and non-functional test results of the new version system, the problem of missing or incorrect test materials was resolved, improving testing efficiency and the accuracy of system delivery.

CN115495361BActive Publication Date: 2026-04-17CHINA CONSTRUCTION BANK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA CONSTRUCTION BANK
Filing Date
2022-09-23
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In existing technologies, the test materials for new version systems contain missing or incorrect information, leading to test failures, affecting test efficiency and system delivery time, and manual inspection is prone to omissions.

Method used

A delivery access inspection method is provided, which obtains the delivery documents, security test results, and non-functional test results of the system to be delivered, and performs integrity checks, correctness checks, and coverage checks to ensure the accuracy and completeness of the materials.

Benefits of technology

It effectively reduces the probability of errors during the testing process, improves testing efficiency, and ensures the accuracy and timeliness of system delivery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115495361B_ABST
    Figure CN115495361B_ABST
Patent Text Reader

Abstract

This application discloses a delivery access check method, apparatus, electronic device, and storage medium. The method includes: acquiring delivery documents, security test results, and non-functional test results of a system to be delivered; performing corresponding check operations on the delivery documents, security test results, and non-functional test results of the system to be delivered; wherein the check operation corresponding to the delivery documents includes at least integrity checks and correctness checks; the check operation corresponding to the security test results includes at least coverage checks, correctness checks, and vulnerability checks; the check operation corresponding to the non-functional test results includes at least integrity checks and correctness checks; if all corresponding check operations are passed, the system to be delivered is determined to have passed the delivery access check; if any one of the corresponding check operations is failed, the system to be delivered is determined to have failed the delivery access check.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of system delivery, and in particular to a delivery access inspection method and apparatus, electronic equipment, and storage medium. Background Technology

[0002] As businesses rapidly innovate and develop, their system development also needs to undergo rapid transformation and continuous system updates. To ensure high-quality system delivery and avoid problems during service provision, it is usually necessary to conduct rapid and effective testing and verification of the functions provided by a new version of the system before delivery.

[0003] Currently, testing of new system versions primarily involves preparing relevant materials and then directly using those materials to begin testing. However, because new systems are newly developed, the test materials often contain missing or incorrect information, leading to test failures. The main approach is to modify the materials based on the reasons for the failure after the test fails, or to manually check the materials beforehand.

[0004] However, analyzing the reasons for test failures and making corresponding modifications afterward will obviously affect the efficiency of testing. Manual inspection is prone to omissions and may lead to test failures, which will also affect the efficiency of testing and thus affect the system delivery time. Summary of the Invention

[0005] In view of the shortcomings of the prior art, this application provides a delivery access inspection method and apparatus, electronic device and storage medium to solve the problem that the existing method is prone to omissions and affects the system testing efficiency.

[0006] To achieve the above objectives, this application provides the following technical solution:

[0007] The first aspect of this application provides a delivery access check method, including:

[0008] Obtain the delivery documents, security test results, and non-functional test results of the system to be delivered.

[0009] The target data of the system to be delivered is subjected to corresponding inspection operations; wherein, the target data includes the delivery documents, the security test results, and the non-functional test results; the inspection operations corresponding to the delivery documents include at least integrity checks and correctness checks; the inspection operations corresponding to the security test results include at least coverage checks, correctness checks, and vulnerability checks; the inspection operations corresponding to the non-functional test results include at least integrity checks and correctness checks.

[0010] If the delivery documents, security test results, and non-functional test results of the system to be delivered all pass the corresponding inspection operations, then the system to be delivered is determined to have passed the delivery access check.

[0011] If any one of the delivery documents, the security test results, and the non-functional test results of the system to be delivered fails any of the corresponding check operations, then the system to be delivered is determined to have failed the delivery access check.

[0012] Optionally, in the above delivery access check method, the target data is the delivery document, and the corresponding check operation on the target data of the system to be delivered includes:

[0013] Verify whether the version package of the delivery document of the system to be delivered submitted is the version package of the version to be delivered;

[0014] If the version package of the delivery document of the system to be delivered is verified to be the version package of the system to be delivered, then according to the delivery document format rules, it is verified whether each key piece of information in the change control table and operation and maintenance handover document in the delivery document is missing and whether they are all correct.

[0015] If all key information in the change control table and operation and maintenance handover documents in the delivery documents is complete and correct, then the delivery documents of the system to be delivered are deemed to have passed the inspection.

[0016] Optionally, in the above-described delivery access inspection method, the target data is the security test result, and the corresponding inspection operation on the target data of the system to be delivered includes:

[0017] Check whether the security test results of the system to be delivered include the plaintext password scanning results and application log sensitive information scanning results of each version of the system to be delivered;

[0018] If the security test results are found to include plaintext password scanning results and application log sensitive information scanning results for each version of the system to be delivered, then it is determined whether the test data of the security test results are complete and meet the format requirements.

[0019] If it is determined that all test data in the security test results are complete and meet the format requirements, check whether there are any security vulnerabilities in the security test results;

[0020] If a security vulnerability is found in the security test results, obtain the vulnerability remediation results information;

[0021] Based on the aforementioned rectification results, determine whether the rectification of the security vulnerability has passed.

[0022] If no security vulnerabilities are found in the security test results, or if it is determined that the remediation of the security vulnerabilities has been approved, then the security test results of the system to be delivered are deemed to have passed the inspection.

[0023] Optionally, the above-described delivery access check method may also include:

[0024] Obtain the non-functional test requirements assessment information of the system to be delivered;

[0025] Verify whether the change description information in the non-functional test requirement assessment information is complete;

[0026] If the change description information in the non-functional test requirement assessment information is found to be complete, analyze whether the system to be delivered has non-functional test requirements based on the non-functional requirement assessment information.

[0027] If the analysis reveals that the system to be delivered has non-functional testing requirements, a prompt will be made to perform non-functional testing on the system to be delivered and upload the results of the non-functional testing.

[0028] Optionally, in the above delivery access inspection method, the target data is the non-functional test result, and the corresponding inspection operation on the target data of the system to be delivered includes:

[0029] According to the non-functional test verification standard, verify whether the test plan, test cases and test report in the non-functional test results are complete.

[0030] If the test plan, test cases, and test report in the non-functional test results are found to be complete, then the non-functional test results of the system to be delivered are deemed to have passed the inspection.

[0031] A second aspect of this application provides a delivery access inspection device, comprising:

[0032] The first acquisition unit is used to acquire the delivery documents, security test results and non-functional test results of the system to be delivered, respectively.

[0033] The document inspection unit is used to perform corresponding inspection operations on the delivery documents of the system to be delivered; wherein, the inspection operations corresponding to the delivery documents include at least integrity checks and correctness checks;

[0034] The first result checking unit is used to perform corresponding checking operations on the security test results of the system to be delivered; wherein, the checking operations corresponding to the security test results include at least coverage checks, correctness checks, and vulnerability checks.

[0035] The second result checking unit is used to perform corresponding checking operations on the non-functional test results of the system to be delivered; wherein, the checking operations corresponding to the non-functional test results include at least integrity checks and correctness checks.

[0036] The first determining unit is configured to determine that the system to be delivered has passed the delivery access check when the delivery documents, the security test results, and the non-functional test results of the system to be delivered have all passed the corresponding check operations.

[0037] The second determining unit is configured to determine that the system to be delivered has failed the delivery access check when any one of the delivery documents, the security test results, and the non-functional test results of the system to be delivered fails any one of the corresponding check operations.

[0038] Optionally, in the above-described delivery access inspection apparatus, the document inspection unit includes:

[0039] The first verification unit is used to verify whether the version package of the delivery document of the system to be delivered is the version package of the system to be delivered.

[0040] The second verification unit is used to verify, when it is found that the version package of the delivery document of the submitted system to be delivered is the version package of the system to be delivered, whether each key piece of information in the change control table and operation and maintenance handover document in the delivery document is missing and whether they are all correct, according to the delivery document format rules.

[0041] The third determining unit is used to determine that the delivery documents of the system to be delivered have passed the inspection when all key information in the change control table and operation and maintenance handover documents in the delivery documents are not missing and are all correct.

[0042] Optionally, in the above-described delivery access inspection apparatus, the first result inspection unit includes:

[0043] The detection unit is used to detect whether the security test results of the system to be delivered include the plaintext password scanning results and application log sensitive information scanning results of each version of the system to be delivered.

[0044] The first judgment unit is used to determine whether the test data of the security test results are complete and conform to the format requirements when the security test results detect that the security test results include the plaintext password scanning results of the configuration of each version of the system to be delivered and the application log sensitive information scanning results.

[0045] The vulnerability checking unit is used to check whether there are security vulnerabilities in the security test results when it is determined that all test data in the security test results are complete and meet the format requirements.

[0046] The second acquisition unit is used to acquire vulnerability remediation result information when a security vulnerability is found in the security test results.

[0047] The second judgment unit is used to determine whether the rectification of the security vulnerability has passed based on the rectification results information.

[0048] The third determining unit is used to determine that the security test results of the system to be delivered have passed the inspection when the security test results show no security vulnerabilities or when it is determined that the rectification of the security vulnerabilities has been passed.

[0049] Optionally, the aforementioned delivery access inspection device further includes:

[0050] The third acquisition unit is used to acquire non-functional test requirement evaluation information of the system to be delivered.

[0051] The third verification unit is used to verify whether the change description information in the non-functional test requirement assessment information is complete.

[0052] The analysis unit is used to analyze whether the system to be delivered has non-functional test requirements when the change description information in the non-functional test requirement assessment information is found to be complete.

[0053] The prompting unit is used to prompt the system to be delivered to perform non-functional testing when it is found that the system to be delivered has non-functional testing requirements, and to upload the results of the non-functional testing.

[0054] Optionally, in the above-described delivery access inspection device, the second result inspection unit includes:

[0055] The fourth verification unit is used to verify whether the test plan, test cases and test report in the non-functional test results are complete according to the non-functional test verification standard.

[0056] The fourth determining unit is used to determine that the non-functional test results of the system to be delivered have passed the inspection when it is verified that the test plan, test cases and test reports in the non-functional test results are complete.

[0057] A third aspect of this application provides an electronic device, comprising:

[0058] Memory and processor;

[0059] The memory is used to store programs;

[0060] The processor is used to execute the program, which, when executed, is specifically used to implement the delivery access check method as described in any of the above.

[0061] A fourth aspect of this application provides a computer storage medium for storing a computer program, which, when executed, implements the delivery access check method as described in any of the preceding claims.

[0062] This application provides a delivery access check method that acquires the delivery documents, security test results, and non-functional test results of the system to be delivered, and then performs corresponding check operations on each of these components. The check operations for the delivery documents include at least integrity and correctness checks; the check operations for the security test results include at least coverage, correctness, and vulnerability checks; and the check operations for the non-functional test results include at least integrity and correctness checks. If all three components of the system to be delivered pass the corresponding check operations, the system is determined to have passed the delivery access check. If any one of these components fails the corresponding check operation, the system is determined to have failed the delivery access check. This method automates the checking of the new system's materials into three parts, effectively ensuring the accuracy and completeness of the materials, reducing the probability of errors during testing, and thus significantly improving the efficiency of functional testing. Attached Figure Description

[0063] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0064] Figure 1 A flowchart of a delivery access check method provided in an embodiment of this application;

[0065] Figure 2 A flowchart illustrating a method for performing corresponding inspection operations on delivery documents of a system to be delivered, as provided in this application embodiment;

[0066] Figure 3 A flowchart illustrating a method for performing corresponding inspection operations on the security test results of a system to be delivered, as provided in this application embodiment;

[0067] Figure 4A flowchart illustrating a non-functional test requirement assessment method provided in this application embodiment;

[0068] Figure 5 A flowchart illustrating a method for performing corresponding inspection operations on the non-functional test results of a system to be delivered, as provided in this application embodiment;

[0069] Figure 6 A schematic diagram of the architecture of a delivery access inspection device provided in an embodiment of this application;

[0070] Figure 7 This is a schematic diagram of the architecture of an electronic device provided in an embodiment of this application. Detailed Implementation

[0071] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0072] In this application, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0073] This application provides a delivery access check method, such as... Figure 1 As shown, the specific steps include:

[0074] S101. Obtain the delivery documents, security test results, and non-functional test results of the system to be delivered.

[0075] It should be noted that, in this embodiment of the application, the inspection of the materials of the system to be delivered is specifically divided into delivery document inspection, security test result inspection, and non-functional test result inspection. Therefore, it is necessary to obtain the delivery documents, security test results, and non-functional test results of the system to be delivered separately.

[0076] Optionally, since the inspection of this data is related and independent, step S102 can be performed on each piece of data as soon as it is acquired. Alternatively, step S102 can be performed together after all three pieces of data are acquired.

[0077] S102. Perform corresponding checks on the delivery documents, security test results, and non-functional test results of the system to be delivered.

[0078] It should be noted that since the target data includes delivery documents, security test results, and non-functional test results, the corresponding inspection operation on the target data of the system to be delivered means that the corresponding inspection operations are performed on the delivery documents, security test results, and non-functional test results of the system to be delivered.

[0079] Specifically, step S102 can be divided into three parts: performing corresponding inspection operations on the delivery documents of the system to be delivered, performing corresponding inspection operations on the security test results of the system to be delivered, and performing corresponding inspection operations on the non-functional test results of the system to be delivered. These three operations are related and independent.

[0080] The checks performed on the delivery documents include at least completeness checks and correctness checks. Since the delivery documents mainly consist of various delivered documents, the main checks performed are on the submitted documents for completeness and correctness.

[0081] The checks performed on security test results should include at least coverage checks, correctness checks, and vulnerability checks. Since security test results are generated and uploaded after the security test, based on the test process data, it is necessary not only to check the correctness of the information but also to check whether the security test was comprehensive and whether any vulnerabilities exist.

[0082] The inspection operations corresponding to the non-functional test results should include at least integrity checks and correctness checks.

[0083] Optionally, in another embodiment of this application, when the target data is data to be delivered, performing corresponding inspection operations on the target data of the system to be delivered is a specific implementation of performing corresponding inspection operations on the delivery documents of the system to be delivered. Figure 2 As shown, a specific implementation method for performing corresponding inspection operations on the delivery documents of the system to be delivered includes:

[0084] S201. Verify whether the version package of the delivery documents of the system to be delivered is the version package of the system to be delivered.

[0085] Because there are many versions of the system, to avoid upload errors, it is necessary to first verify whether the version package of the submitted delivery file of the system to be delivered is the version package of the version to be delivered. If the verification shows that the version package of the submitted delivery file of the system to be delivered is the version package of the version to be delivered, then step S202 can be executed.

[0086] S202. According to the delivery document format rules, verify whether the key information in the change control table and operation and maintenance handover document in the delivery document is missing and whether it is correct.

[0087] It should be noted that, in this embodiment, the delivery documents mainly include the system version package, change control table, and operation and maintenance handover documents. Of course, other documents may also be included depending on the actual situation.

[0088] Therefore, in this embodiment of the application, after determining that the version package is correct, it is necessary to verify whether other files are correct.

[0089] If all key information in the change control table and operation and maintenance handover documents in the verification delivery documents is complete and correct, then step S203 can be executed.

[0090] S203. Confirm that the delivery documents for the system to be delivered have passed inspection.

[0091] Correspondingly, if the verification result in step S201 or step S202 is negative, it is determined that the delivery documents of the system to be delivered have failed the inspection.

[0092] Optionally, in another embodiment of this application, when the target data is a security test result, performing a corresponding inspection operation on the target data of the system to be delivered is one implementation of performing a corresponding inspection operation on the security test result of the system to be delivered. Figure 3 As shown, one implementation method for performing corresponding inspection operations on the security test results of the system to be delivered includes:

[0093] S301. Check whether the security test results of the system to be delivered include the plaintext password scanning results and application log sensitive information scanning results of each version of the system to be delivered.

[0094] If the security test results include plaintext password scanning results and application log sensitive information scanning results for each version of the system to be delivered, it means that the scanning of plaintext passwords and log sensitive information has been fully covered, so step S302 can be executed next.

[0095] S302. Determine whether all test data in the safety test results are complete and meet the format requirements.

[0096] More specifically, security test results include the phases of the test, specific time points, test tools, scanning strategies, etc., so it is necessary to check whether all this information has been uploaded and whether the format meets the requirements.

[0097] If it is determined that all test data in the security test results are complete and meet the format requirements, then step S303 can be executed.

[0098] S303. Check the security test results for any security vulnerabilities.

[0099] Specifically, if a security vulnerability is found in the security test results, relevant personnel need to rectify the vulnerability and upload the rectification results. Therefore, if a security vulnerability is found in the security test results, step S304 is executed. If no security vulnerability is found in the security test results, steps S304 and S305 do not need to be executed, so step S306 can be executed directly.

[0100] S304. Obtain information on the results of vulnerability remediation.

[0101] It should be noted that vulnerability remediation results are also part of the security test results, so they can be added to the security test results.

[0102] S305. Based on the information on the implementation and rectification results, determine whether the rectification of security vulnerabilities has passed.

[0103] If it is determined that the remediation of the security vulnerability has been approved, then step S306 is executed.

[0104] S306. Confirm that the security test results of the system to be delivered pass the inspection.

[0105] Optionally, non-functional testing may not be required for the system to be delivered. If non-functional testing is not required, then there is no need to obtain and inspect the results. Therefore, before obtaining the results, the non-functional testing requirements need to be assessed in advance to determine whether non-functional testing is necessary. Figure 4 As shown in the embodiment of this application, a non-functional test requirement assessment method includes:

[0106] S401. Obtain non-functional test requirements assessment information for the system to be delivered.

[0107] S402. Verify whether the description of changes in the non-functional test requirements assessment information is complete.

[0108] Optionally, the change description information may include one or more of the following: changes in online transactions, database changes, changes in non-functional requirements indicators, system changes, changes in basic software, and changes in operations.

[0109] If the change description information in the non-functional test requirement assessment information is found to be complete, it means that the change description information can be used to accurately assess the requirements, so step S403 is executed at this time.

[0110] S403. Analyze whether the system to be delivered has non-functional testing requirements based on the non-functional requirements assessment information.

[0111] It should be noted that the specific circumstances under which non-functional testing is required can be set according to the requirements, and corresponding rules can be set to assess whether there is a need for non-functional testing.

[0112] If the analysis reveals that the system to be delivered has non-functional testing requirements, then step S404 is executed.

[0113] S404. Prompt to perform non-functional testing on the system to be delivered and upload the results of the non-functional testing.

[0114] It should be noted that when non-functional testing is required, developers can write a test plan, then write test cases based on the test plan, and finally write a test report based on the test data. The test plan, test cases, and report are then uploaded as a single non-functional test result.

[0115] Optionally, in another embodiment of this application, when the target data is a non-functional test result, performing a corresponding inspection operation on the target data of the system to be delivered is one implementation of performing a corresponding inspection operation on the non-functional test results of the system to be delivered. Figure 5 As shown, one implementation method for performing corresponding inspection operations on the non-functional test results of the system to be delivered includes:

[0116] S501. According to the non-functional test verification standard, verify whether the test plan, test cases and test report in the non-functional test results are complete.

[0117] If the test plan, test cases, and test report in the non-functional test results are found to be complete, then proceed to step S502.

[0118] S502. Confirm that the non-functional test results of the system to be delivered pass the inspection.

[0119] S103. Determine whether the delivery documents, security test results, and non-functional test results of the system to be delivered have all passed the corresponding inspection operations.

[0120] If the delivery documents, security test results, and non-functional test results of the system to be delivered all pass their respective check operations, then step S104 is executed. If any one of the delivery documents, security test results, and non-functional test results of the system to be delivered fails any one of their respective check operations, then step S105 is executed.

[0121] S104. Determine if the system to be delivered passes the delivery access check.

[0122] S105. It is determined that the system to be delivered has failed the delivery access check.

[0123] This application provides a delivery access check method. It acquires the delivery documents, security test results, and non-functional test results of the system to be delivered, and then performs corresponding check operations on each of these components. The check operations for the delivery documents include at least integrity and correctness checks; the check operations for the security test results include at least coverage, correctness, and vulnerability checks; and the check operations for the non-functional test results include at least integrity and correctness checks. If all three components of the system to be delivered pass the corresponding check operations, the system is determined to have passed the delivery access check. If any one of these components fails the corresponding check operation, the system is determined to have failed the delivery access check. This method automates the checking of the new system's materials into three parts, effectively ensuring the accuracy and completeness of the materials, reducing the probability of errors during testing, and thus significantly improving the efficiency of functional testing.

[0124] Another embodiment of this application provides a delivery access inspection device, such as... Figure 6 As shown, it includes:

[0125] The first acquisition unit 601 is used to acquire the delivery documents, security test results and non-functional test results of the system to be delivered.

[0126] Document inspection unit 602 is used to perform corresponding inspection operations on the delivery documents of the system to be delivered.

[0127] The inspection operations corresponding to the delivered documents include at least integrity checks and correctness checks.

[0128] The first result inspection unit 603 is used to perform corresponding inspection operations on the security test results of the system to be delivered.

[0129] The inspection operations corresponding to the security test results include at least coverage checks, correctness checks, and vulnerability checks.

[0130] The second result inspection unit 604 is used to perform corresponding inspection operations on the non-functional test results of the system to be delivered.

[0131] Among them, the inspection operations corresponding to the non-functional test results include at least integrity checks and correctness checks.

[0132] The first determining unit 605 is used to determine that the system to be delivered has passed the delivery access check when the delivery documents, security test results and non-functional test results of the system to be delivered have all passed the corresponding check operations.

[0133] The second determining unit 606 is used to determine that the system to be delivered has failed the delivery access check when any one of the delivery documents, security test results, and non-functional test results of the system to be delivered fails any one of the corresponding check operations.

[0134] Optionally, in another embodiment of the delivery access inspection apparatus provided in this application, the document inspection unit includes:

[0135] The first verification unit is used to verify whether the version package of the delivery documents of the submitted system to be delivered is the version package of the version to be delivered.

[0136] The second verification unit is used to verify, when it is determined that the version package of the delivery document of the submitted system to be delivered is the version package of the system to be delivered, whether the change control table and the operation and maintenance handover document in the delivery document are missing, and whether they are all correct, according to the delivery document format rules.

[0137] The third determining unit is used to determine that the delivery documents of the system to be delivered have passed the inspection if all key information in the change control table and operation and maintenance handover documents in the verification delivery documents is complete and correct.

[0138] Optionally, in another embodiment of the delivery access inspection apparatus provided in this application, the first result inspection unit includes:

[0139] The detection unit is used to detect whether the security test results of the system to be delivered include plaintext password scanning results and application log sensitive information scanning results for each version of the system to be delivered.

[0140] The first judgment unit is used to determine whether the various test data in the security test results are complete and meet the format requirements when the security test results include plaintext password scanning results of various versions of the system to be delivered and application log sensitive information scanning results.

[0141] The vulnerability checking unit is used to check whether there are security vulnerabilities in the security test results when it is determined that all test data in the security test results are complete and meet the format requirements.

[0142] The second acquisition unit is used to acquire vulnerability remediation result information when security vulnerabilities are found in the security test results.

[0143] The second judgment unit is used to determine whether the rectification of security vulnerabilities is successful based on the information on the implementation and rectification results.

[0144] The third determining unit is used to determine that the security test results of the system to be delivered have passed the inspection when no security vulnerabilities are found in the security test results or when it is determined that the rectification of security vulnerabilities has been passed.

[0145] Optionally, in another embodiment of the delivery access inspection device provided in this application, the device further includes:

[0146] The third acquisition unit is used to acquire non-functional test requirement assessment information for the system to be delivered.

[0147] The third verification unit is used to verify whether the change description information in the non-functional test requirement assessment information is complete.

[0148] The analysis unit is used to analyze whether the system to be delivered has non-functional test requirements when the change description information in the non-functional test requirement assessment information is found to be complete.

[0149] The prompting unit is used to prompt the system to perform non-functional testing when it is found that the system to be delivered has non-functional testing requirements, and to upload the non-functional test results.

[0150] Optionally, in another embodiment of the delivery access inspection apparatus provided in this application, the second result inspection unit includes:

[0151] The fourth verification unit is used to verify whether the test plan, test cases, and test report in the non-functional test results are complete, according to the non-functional test verification standard.

[0152] The fourth determining unit is used to determine that the non-functional test results of the system to be delivered have passed the inspection when the test plan, test cases and test reports in the non-functional test results are found to be complete.

[0153] It should be noted that the specific working process of each unit provided in the above embodiments of this application can be referred to the implementation process of the corresponding steps in the above method embodiments, and will not be repeated here.

[0154] Another embodiment of this application provides an electronic device, such as... Figure 7As shown, it includes:

[0155] Memory 701 and processor 702.

[0156] The memory 701 is used to store the program.

[0157] The processor 702 is used to execute a program stored in the memory 701, which, when executed, is specifically used to implement the delivery admission check method provided in any of the above embodiments.

[0158] Another embodiment of this application provides a computer storage medium for storing a computer program, which, when executed, implements the delivery access check method provided in any of the above embodiments.

[0159] Computer storage media, including both permanent and non-permanent, removable and non-removable media, can store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0160] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0161] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method of delivering an admission check, characterized by, include: Obtain the delivery documents, security test results, and non-functional test results of the system to be delivered; wherein, the delivery documents include at least the version package, change control table, and operation and maintenance handover documents; The target data of the system to be delivered is subject to corresponding inspection operations; wherein, the target data includes the delivery documents, the security test results, and the non-functional test results; the inspection operations corresponding to the delivery documents include at least integrity checks and correctness checks; the inspection operations corresponding to the security test results include at least coverage checks, correctness checks, and vulnerability checks; the inspection operations corresponding to the non-functional test results include at least integrity checks and correctness checks; the integrity check of the delivery documents involves checking whether any key information in the change control table and the operation and maintenance handover document is missing; the vulnerability check involves checking whether there are any vulnerabilities in the security test results and whether they have been rectified; If the delivery documents, security test results, and non-functional test results of the system to be delivered all pass the corresponding inspection operations, then the system to be delivered is determined to have passed the delivery access check. If any one of the delivery documents, the security test results, and the non-functional test results of the system to be delivered fails any of the corresponding check operations, then the system to be delivered is determined to have failed the delivery access check.

2. The method of claim 1, wherein, The target data is the delivery document, and the corresponding inspection operation on the target data of the system to be delivered includes: Verify whether the version package of the delivery document of the system to be delivered submitted is the version package of the version to be delivered; If the version package of the delivery document of the system to be delivered is verified to be the version package of the system to be delivered, then according to the delivery document format rules, it is verified whether each key piece of information in the change control table and operation and maintenance handover document in the delivery document is missing and whether they are all correct. If all key information in the change control table and operation and maintenance handover documents in the delivery documents is complete and correct, then the delivery documents of the system to be delivered are deemed to have passed the inspection.

3. The method of claim 1, wherein, The target data is the security test result, and the corresponding inspection operation on the target data of the system to be delivered includes: Check whether the security test results of the system to be delivered include the plaintext password scanning results and application log sensitive information scanning results of each version of the system to be delivered; If the security test results are found to include plaintext password scanning results and application log sensitive information scanning results for each version of the system to be delivered, then it is determined whether the test data of the security test results are complete and meet the format requirements. If it is determined that all test data in the security test results are complete and meet the format requirements, check whether there are any security vulnerabilities in the security test results; If a security vulnerability is found in the security test results, obtain the vulnerability remediation results information; Based on the vulnerability remediation results, determine whether the remediation of the security vulnerability has passed; If no security vulnerabilities are found in the security test results, or if it is determined that the remediation of the security vulnerabilities has been approved, then the security test results of the system to be delivered are deemed to have passed the inspection.

4. The method of claim 1, wherein, Also includes: Obtain the non-functional test requirements assessment information of the system to be delivered; Verify whether the change description information in the non-functional test requirement assessment information is complete; If the change description information in the non-functional test requirement assessment information is found to be complete, analyze whether the system to be delivered has non-functional test requirements based on the non-functional requirement assessment information. If the analysis reveals that the system to be delivered has non-functional testing requirements, a prompt will be made to perform non-functional testing on the system to be delivered and upload the results of the non-functional testing.

5. The method according to claim 1, characterized in that, The target data is the non-functional test result, and the corresponding inspection operation on the target data of the system to be delivered includes: According to the non-functional test verification standard, verify whether the test plan, test cases and test report in the non-functional test results are complete. If the test plan, test cases, and test report in the non-functional test results are found to be complete, then the non-functional test results of the system to be delivered are deemed to have passed the inspection.

6. A delivery admission checking apparatus characterized by comprising: include: The first acquisition unit is used to acquire the delivery documents, security test results, and non-functional test results of the system to be delivered; wherein, the delivery documents include at least a version package, a change control table, and an operation and maintenance handover document; The document inspection unit is used to perform corresponding inspection operations on the delivery documents of the system to be delivered; wherein, the inspection operations corresponding to the delivery documents include at least integrity checks and correctness checks; the integrity check of the delivery documents is to check whether each key piece of information in the change control table and the operation and maintenance handover document is missing; The first result checking unit is used to perform corresponding checking operations on the security test results of the system to be delivered; wherein, the checking operations corresponding to the security test results include at least coverage checking, correctness checking and vulnerability checking; the vulnerability checking is to check whether there are vulnerabilities in the security test results and whether they have been rectified. The second result checking unit is used to perform corresponding checking operations on the non-functional test results of the system to be delivered; wherein, the checking operations corresponding to the non-functional test results include at least integrity checks and correctness checks. The first determining unit is configured to determine that the system to be delivered has passed the delivery access check when the delivery documents, the security test results, and the non-functional test results of the system to be delivered have all passed the corresponding check operations. The second determining unit is configured to determine that the system to be delivered has failed the delivery access check when any one of the delivery documents, the security test results, and the non-functional test results of the system to be delivered fails any one of the corresponding check operations.

7. The apparatus of claim 6, wherein, The document inspection unit includes: The first verification unit is used to verify whether the version package of the delivery document of the system to be delivered is the version package of the system to be delivered. The second verification unit is used to verify, when it is found that the version package of the delivery document of the submitted system to be delivered is the version package of the system to be delivered, whether each key piece of information in the change control table and operation and maintenance handover document in the delivery document is missing and whether they are all correct, according to the delivery document format rules. The third determining unit is used to determine that the delivery documents of the system to be delivered have passed the inspection when all key information in the change control table and operation and maintenance handover documents in the delivery documents are not missing and are all correct.

8. The apparatus of claim 6, wherein, The first result checking unit includes: The detection unit is used to detect whether the security test results of the system to be delivered include the plaintext password scanning results and application log sensitive information scanning results of each version of the system to be delivered. The first judgment unit is used to determine whether the test data of the security test results are complete and conform to the format requirements when the security test results detect that the security test results include the plaintext password scanning results of the configuration of each version of the system to be delivered and the application log sensitive information scanning results. The vulnerability checking unit is used to check whether there are security vulnerabilities in the security test results when it is determined that all test data in the security test results are complete and meet the format requirements. The second acquisition unit is used to acquire vulnerability remediation result information when a security vulnerability is found in the security test results. The second judgment unit is used to determine whether the remediation of the security vulnerability is successful based on the vulnerability remediation result information. The third determining unit is used to determine that the security test results of the system to be delivered have passed the inspection when the security test results show no security vulnerabilities or when it is determined that the rectification of the security vulnerabilities has been passed.

9. An electronic device, comprising: include: Memory and processor; The memory is used to store programs; The processor is used to execute the program, which, when executed, is specifically used to implement the delivery access check method as described in any one of claims 1 to 5.

10. A computer storage medium, characterized in that, Used to store a computer program, which, when executed, implements the delivery access check method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Software delivery data checking method and device

    CN113448613A