Prosecution Insights
Last updated: August 30, 2026
Application No. 18/733,061

COMMUNICATION SYSTEM, AUTHENTICATION METHOD, AND STORING MEDIUM

Non-Final OA §102§103
Filed
Jun 04, 2024
Priority
Jun 07, 2023 — JP 2023-094056
Examiner
YI, ALEXANDER J.
Art Unit
2643
Tech Center
2600 — Communications
Assignee
Toyota Motor Corporation
OA Round
1 (Non-Final)
68%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 68% — above average
68%
Career Allowance Rate
318 granted / 466 resolved
+6.2% vs TC avg
Strong +56% interview lift
Without
With
+56.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
12 currently pending
Career history
492
Total Applications
across all art units

Statute-Specific Performance

§101
1.4%
-38.6% vs TC avg
§103
67.4%
+27.4% vs TC avg
§102
22.1%
-17.9% vs TC avg
§112
7.4%
-32.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 466 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-2, 10, and 15 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Zou (US 2014/0282902 A1). Regarding claim 1, Zou teaches a communication system ([0051], “authentication network system 204”) comprising: a storage configured to store authentication data for authenticating a mobile communication terminal ([0055], “authentication datastore 212 stores authentication information, including onboarding information, relating to the user device 202. The authentication datastore 212 can store device profiles relating to the configuration of the device”); a gateway configured to accommodate access from an untrusted first communication network ([0046], “The network gateway 108 can provide access for an IT administrator to administer one or more of the trusted network 110 and portions of the untrusted network 112 that the user device 104 is seeking to access”); and a controller configured to execute: authenticating the mobile communication terminal connected through the gateway via the first communication network, using the authentication data ([0056], “the authentication server engine 214 (~controller) can provide services to authenticate the user device 202 to a trusted network and/or an untrusted network, authorize access of the user device 202 (or a user thereof) to resources of the trusted network and/or the untrusted network, and/or to account for usage of these services”; [0049], “Access to the untrusted network 112 may or may not be administered by the network gateway 108 and/or the split authentication network system 106”; authentication is performed via comparison against the authentication information stored in the authentication datastore; [0055], “the authentication datastore 212 stores authentication information, including onboarding information, relating to the user device 202. The authentication datastore 212 can store device profiles relating to the configuration of the device. For example, the authentication datastore 212 can store how the user device 202 has been authenticated for network access previously. The authentication datastore 212 can also contain user profiles, such as how a particular user has authenticated to a trusted network and/or an untrusted network previously. For instance, the authentication datastore 212 can store a username and a password for each user on the system. The authentication datastore 212 can also store permissions associated with one or more of the authentication server engines 214-1 to 214-n”); and providing first information about a result of the authentication of the mobile communication terminal, to a first server which is a communication destination of the mobile communication terminal ([0056], “the authentication server engine 214 can provide services to authenticate the user device 202 to a trusted network and/or an untrusted network, authorize access of the user device 202 (or a user thereof) to resources of the trusted network and/or the untrusted network, and/or to account for usage of these services”, wherein the authentication server engine 214 provides the result of the authentication of the mobile communication terminal by verifying digital certificates and the trusted network and/or the untrusted network contains the first server). Regarding claim 2, Zou teaches the communication system according to claim 1, wherein the controller relays communication from the authenticated mobile communication terminal to the first server ([0056], “the authentication server engine (~controller) 214 can provide services to authenticate the user device 202 to a trusted network and/or an untrusted network, authorize access of the user device 202 (or a user thereof) to resources of the trusted network and/or the untrusted network (~first server of the network), and/or to account for usage of these services”). Regarding claim 10, Zou teaches an authentication method comprising: a first step of authenticating a mobile communication terminal ([0056], authentication server engine 214 can provide services to authenticate the user device 202 to a trusted network and/or an untrusted network, authorize access of the user device 202 (or a user thereof) to resources of the trusted network and/or the untrusted network, and/or to account for usage of these services”) connected through a gateway configured to accommodate access from an untrusted first communication network ([0046], “The network gateway 108 can provide access for an IT administrator to administer one or more of the trusted network 110 and portions of the untrusted network 112 that the user device 104 is seeking to access”), using authentication data stored in a storage ([0055], “authentication datastore 212 stores authentication information, including onboarding information, relating to the user device 202. The authentication datastore 212 can store device profiles relating to the configuration of the device”); and a second step of providing first information about a result of the authentication of the mobile communication terminal, to a first server which is a communication destination of the mobile communication terminal ([0056], “the authentication server engine 214 can provide services to authenticate the user device 202 to a trusted network and/or an untrusted network, authorize access of the user device 202 (or a user thereof) to resources of the trusted network and/or the untrusted network, and/or to account for usage of these services”, wherein the authentication server engine 214 provides the result of the authentication of the mobile communication terminal by verifying digital certificates and the trusted network and/or the untrusted network contains the first server). Regarding claim 15, Zou teaches a non-transitory computer readable storing medium recording a computer program for causing a computer to perform the authentication method according to claim 10 ([0035], “Nevertheless, it should be understood that for software to run, if necessary, it is moved to a computer-readable location appropriate for processing, and for illustrative purposes, that location is referred to as the memory in this paper. Even when software is moved to the memory for execution, the processor will typically make use of hardware registers to store values associated with the software, and local cache that, ideally, serves to speed up execution”). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 3 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Zou in view of Fan ("Terminal Authentication Method, Device and System", WO 2017107745 A1, pub. date 2017-06-29). Regarding claim 3, Zou teaches the communication system according to claim 1. Zou does not explicitly teach wherein the controller authenticates the first server using an electronic certificate corresponding to the first server before authenticating the mobile communication terminal. However, Fan teaches wherein a controller authenticates a first server using an electronic certificate corresponding to the first server before authenticating a mobile communication terminal (pg. 4, par. 7 - pg. 5, par. 1, “3GPP AAA server (~controller) is further configured to: after receiving the handshake message sent by the access gateway, return a service certificate to the access gateway; and the terminal is further configured to receive the access And the server certificate is sent by the gateway, and the server certificate is verified (~authenticated). After the server certificate is verified, the terminal certificate is sent to the access gateway; the 3GPP AAA server (~controller) is further configured to Receiving and verifying (~authenticating) the terminal certificate sent by the access gateway”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Fan with the teaching of Zou in order to establish mutual trust, prevents unwanted interceptions, and ensure the mobile terminal does not leak sensitive credentials to a fake or rogue server. Regarding claim 11, Zou teaches the authentication method according to claim 10. Zou does not explicitly teach further comprising a third step of authenticating the first server using an electronic certificate corresponding to the first server, the third step being executed before the first step. However, Fan teaches further comprising a third step of authenticating a first server using an electronic certificate corresponding to the first server, the third step being executed before a first step (pg. 4, par. 7 - pg. 5, par. 1, “3GPP AAA server (~controller) is further configured to: after receiving the handshake message sent by the access gateway, return a service certificate to the access gateway; and the terminal is further configured to receive the access And the server certificate is sent by the gateway, and the server certificate is verified (~authenticated). After the server certificate is verified, the terminal certificate is sent to the access gateway; the 3GPP AAA server (~controller) is further configured to Receiving and verifying (~authenticating) the terminal certificate sent by the access gateway”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Fan with the teaching of Zou in order to establish mutual trust, prevents unwanted interceptions, and ensure the mobile terminal does not leak sensitive credentials to a fake or rogue server. Claims 4-5 and 12-13 are rejected under 35 U.S.C. 103 as being unpatentable over Zou in view of Fan, further in view of Choi ("Notification Server Using Blockchain-based Mobile Hacking Prevention Process and Notification Method Using the Same", KR 20210140804 A, pub. date 2021-11-23), and further in view Peng ("Method and Apparatus for Processing Vehicle Upgrade Packages", JP 2023501665 A, pub. date 2023-01-18). Regarding claim 4, Zou in view of Fan teaches the communication system according to claim 3. The combination does not explicitly teach wherein the controller further executes providing second information about a result of the authentication of the first server to the authenticated mobile communication terminal. However, Choi teaches wherein a controller further executes providing second information about a result of an authentication to an authenticated mobile communication terminal (pg. 36, par. 7, “notification server, characterized in that hashing the value once more and transmitting it to the authentication server, receiving the authentication result from the authentication server, and storing the notification (~result of an authentication) notification document in the master user terminal when it is authenticated (~authenticated mobile communication terminal)”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Choi with the teaching of Zou as modified by Fan in order to inform the mobile device of the authentication outcome, specifically to confirm success or failure, enable session continuity, or trigger next steps. The combination does not explicitly teach that the authentication is of a first server. However, Peng teaches an authentication of a first server (pg. 6, par. 1, the first terminal may check the server’s digital certificate in the PKI to enforce authentication of the server“). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Peng with the teaching of Zou as modified by Fan and Choi in order to verify identity, protect data, and block bad users and ensure that a user or device trying to log in is who they claim to be before letting them inside a system. Regarding claim 5, Zou in view of Fan, further in view of Choi, and further in view of Peng teaches the communication system according to claim 4, further comprising the mobile communication terminal, wherein the mobile communication terminal treats the first server, as a trustable communication destination (Zou [0056], “the authentication server engine 214 can provide services to authenticate the user device 202 to a trusted network and/or an untrusted network, authorize access of the user device 202 (or a user thereof) to resources of the trusted network and/or the untrusted network, and/or to account for usage of these services”, wherein the mobile communication terminal treats the first server, as a trustable communication destination). Zou does not explicitly teach the second information which has been provided. However, Choi teaches providing second information (pg. 36, par. 7, “notification server (~controller), characterized in that hashing the value once more and transmitting it to the authentication server, receiving the authentication result from the authentication server, and storing (~providing second information) the notification (~result of an authentication of a first server) notification document in the master user terminal when it is authenticated (~authenticated mobile communication terminal)”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Choi with the teaching of Zou as modified by Fan, Choi, and Peng in order to inform the mobile device of the authentication outcome, specifically to confirm success or failure, enable session continuity, or trigger next steps. The combination of Zou, Fan , and Choi does not explicitly teach that the second information is about a first server. However, Peng further teaches information of a first server (pg. 6, par. 1, the first terminal may check the server’s digital certificate in the PKI to enforce authentication of the server“). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Peng with the teaching of Zou as modified by Fan, Choi, and Peng in order to verify identity, protect data, and block bad users and ensure that a user or device trying to log in is who they claim to be before letting them inside a system. Regarding claim 12, Zou in view of Fan teaches the authentication method according to claim 11. The combination does not explicitly teach further comprising a fourth step of providing second information about a result of the authentication of the first server to the authenticated mobile communication terminal. However, Choi teaches further comprising a fourth step of providing second information about a result of an authentication to an authenticated mobile communication terminal (pg. 36, par. 7, “notification server, characterized in that hashing the value once more and transmitting it to the authentication server, receiving the authentication result from the authentication server, and storing the notification (~result of an authentication) notification document in the master user terminal when it is authenticated (~authenticated mobile communication terminal)”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Choi with the teaching of Zou as modified by Fan in order to inform the mobile device of the authentication outcome, specifically to confirm success or failure, enable session continuity, or trigger next steps. The combination does not explicitly teach that the authentication is of a first server. However, Peng teaches an authentication of a first server (pg. 6, par. 1, the first terminal may check the server’s digital certificate in the PKI to enforce authentication of the server“). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Peng with the teaching of Zou as modified by Fan and Choi in order to verify identity, protect data, and block bad users and ensure that a user or device trying to log in is who they claim to be before letting them inside a system. Regarding claim 13, Zou in view of Fan, further in view of Choi, and further in view of Peng teaches the authentication method according to claim 12. wherein the mobile communication terminal treats the first server, as a trustable communication destination (Zou [0056], “the authentication server engine 214 can provide services to authenticate the user device 202 to a trusted network and/or an untrusted network, authorize access of the user device 202 (or a user thereof) to resources of the trusted network and/or the untrusted network, and/or to account for usage of these services”, wherein the mobile communication terminal treats the first server, as a trustable communication destination). Zou does not explicitly teach the second information which has been provided. However, Choi teaches providing second information (pg. 36, par. 7, “notification server (~controller), characterized in that hashing the value once more and transmitting it to the authentication server, receiving the authentication result from the authentication server, and storing (~providing second information) the notification (~result of an authentication of a first server) notification document in the master user terminal when it is authenticated (~authenticated mobile communication terminal)”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Choi with the teaching of Zou in order to inform the mobile device of the authentication outcome, specifically to confirm success or failure, enable session continuity, or trigger next steps. The combination does not explicitly teach that the second information is about a first server. However, Peng further teaches information of a first server (pg. 6, par. 1, the first terminal may check the server’s digital certificate in the PKI to enforce authentication of the server“). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Peng with the teaching of Zou as modified by Fan, Choi, and Peng in order to verify identity, protect data, and block bad users and ensure that a user or device trying to log in is who they claim to be before letting them inside a system. Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Zou in view of Akagami ("Communication Terminal, Communication System, Communication Terminal Control Method, and Program", WO 2018173627 A1, pub. date 2018-09-27), and further in view of Wolbach (US 9565185 B2). Regarding claim 6, Zou teaches the communication system according to claim 1. Zou does not explicitly teach further comprising a second gateway configured to connect to a cellular communication network, wherein the controller authenticates the mobile communication terminal using the same authentication data in a case of the mobile communication terminal having connected via the gateway and in a case of the mobile communication terminal having connected via the second gateway. However, Akagami teaches further comprising a second gateway configured to connect to a communication network (pg. 4, par. 6, “The authentication server 60 authenticates whether the terminal 100 is connectable to the external communication network 70, for example, in response to a request from the second gateway device 40”), wherein a controller authenticates a mobile communication terminal using authentication data in a case of a mobile communication terminal having connected via a gateway and in a case of the mobile communication terminal having connected via a second gateway (pg. 4, pars. 5-6, “requests authentication from the authentication server 60, the detour relay device 50 uses the first gateway device 30 and the external communication network for data related to authentication. Relay to 70. The authentication server 60 authenticates whether the terminal 100 is connectable to the external communication network 70, for example, in response to a request from the second gateway device 40”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Akagami with the teaching of Zou in order to enable seamless roaming, consistent identity verification, and uninterrupted session continuity when the mobile terminal moves or switches connection points. The combination does not explicitly teach that the communication network is a cellular communication network and using the using the authentication data is using the same authentication data. However, Wolbach teaches a cellular communication network (pg. 16, par. 5 – pg. 17, par. 1, “A communications component 1110 interfaces to the processor 1102 to facilitate wired/wireless communication with external systems, e.g., cellular networks”) and using same authentication data (pg. 23, claim 15, “in response to the receiving the authentication data associated with the second gateway device, facilitating communication of the first gateway device with the second gateway device of the wireless network gateway”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Wolbach with the teaching of Zou as modified by Akagami in order to provide redundancy, load balancing, and network isolation to ensure high availability and separate traffic types; and to provide simplified user management, seamless single sign-on (SSO), and reduced administrative overhead. Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Zou in view of Tao ("User Authentication Data Switching Processing Method, Communication Device and Readable Storage Medium", CN 115866581 A, pub. date 2023-03-28). Regarding claim 7, Zou teaches the communication system according to claim 1. Zou does not explicitly teach wherein the authentication data is data corresponding to SIM profile information that the mobile communication terminal includes. However Tao teaches wherein the authentication data is data corresponding to SIM profile information that the mobile communication terminal includes (pg. 6, par. 3, “authentication data (SIM Profile)”; pg. 6, par. 4, “wherein the SIM Profile is used for authentication in the mobile communication network access process”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Tao with the teaching of Zou in order to verify the subscriber's identity, enable secure access to the cellular network, and generate cryptographic keys for data privacy using stored identifiers like the IMSI and secret authentication keys. Regarding claim 14, Zou teaches the authentication method according to claim 10. Zou does not explicitly teach wherein the authentication data is data corresponding to SIM profile information that the mobile communication terminal includes. However Tao teaches wherein authentication data is data corresponding to SIM profile information that mobile communication terminal includes (pg. 6, par. 3, “authentication data (SIM Profile)”; pg. 6, par. 4, “wherein the SIM Profile is used for authentication in the mobile communication network access process”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Tao with the teaching of Zou in order to verify the subscriber's identity, enable secure access to the cellular network, and generate cryptographic keys for data privacy using stored identifiers like the IMSI and secret authentication keys. Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Zou in view of Tao, and further in view of van der Laak (US 20120129513 A1). Regarding claim 8, Zou in view Tao teaches the communication system according to claim 7. The combination does not explicitly teach wherein the SIM profile information is issued by a business operator that operates the communication system. However, van der Laak teaches wherein SIM profile information is issued by a business operator that operates a communication system ([0075], “a service provider may provide SIM profile information 530”; [0002], “cellular networks are privately owned by service providers that operate the cellular network for profit”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of van der Laak with the teaching of Zou as modified by Tao in order to provide guaranteed network compatibility, secured cryptographic authentication, and instant out-of-the-box service access. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Zou in view of Liu ("A Method for Realizing Communication Module, Communication Method and System for ESIM Remote Configuration", CN 110446201 A, pub. date 2019-11-12). Regarding claim 9, Zou teaches the communication system according to claim 1. Zou does not explicitly teach further comprising the mobile communication terminal, wherein the mobile communication terminal includes an eUICC (embedded universal integrated circuit card); and the authentication data is data corresponding to SIM profile information that the eUICC includes. However, Liu teaches further comprising a mobile communication terminal, wherein the mobile communication terminal includes an eUICC (embedded universal integrated circuit card) (pg. 3, par. 1, “communication module is integrated in the terminal device, the communication module comprises a module unit”); and authentication data is data corresponding to SIM profile information that the eUICC includes (pg. 12, par. 5, “eUICCInfo2 (version comprises a version supported by the Profile SIM ... eUICC authentication data“). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Liu with the teaching of Zou in order to enable remote, over-the-air management and secure network switching, letting terminals to securely verify identity and connect to different mobile operators without physical SIM card swaps. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALEXANDER YI whose telephone number is (571)270-7696. The examiner can normally be reached on Monday-Friday from 8:00 am to 5:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, JINSONG HU, can be reached on (571) 272-3965. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /ALEXANDER YI/ Examiner, Art Unit 2643 /JINSONG HU/ Supervisory Patent Examiner, Art Unit 2643
Read full office action

Prosecution Timeline

Jun 04, 2024
Application Filed
Aug 10, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12720295
ENHANCEMENTS IN MOBILITY HISTORY INFORMATION
4y 6m to grant Granted Aug 25, 2026
Patent 12713226
METHOD AND APPARATUS FOR CONTROLLING EXECUTION MODE OF FUNCTION BEING EXECUTED BY USER EQUIPMENT IN WIRELESS COMMUNICATION SYSTEM
3y 6m to grant Granted Aug 18, 2026
Patent 12712963
COMMUNICATION METHOD AND ELECTRONIC DEVICE
2y 11m to grant Granted Aug 18, 2026
Patent 12689885
SUPPORTING MULTIPLE EUICC PROFILES
3y 8m to grant Granted Jul 21, 2026
Patent 12684655
Communication Device
3y 1m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
68%
Grant Probability
99%
With Interview (+56.3%)
3y 4m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 466 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month