User Device with SIM detects a Passpoint-enabled Wi-Fi network.
The device checks its Passpoint profile and determines that EAP-SIM is supported by the network.
The device sends an authentication request using EAP-SIM, including the IMSI (International Mobile Subscriber Identity) from the SIM card.
The Wi-Fi network’s AP forwards the request to the RADIUS server, which queries the user’s mobile network for authentication.
The mobile network verifies the SIM credentials using the HLR/HSS and sends back an authentication challenge.
The device responds to the challenge using the SIM card.
Upon successful verification, the RADIUS server grants access to the Wi-Fi network, and the user is automatically connected.
Certificate-based authentication
This method allows with Wi-Fi Passpoint involves using EAP-TLS (Extensible Authentication Protocol - Transport Layer Security), where client devices authenticate to the Wi-Fi network using digital certificates rather than usernames, passwords, or SIM credentials. This ensures a high level of security, especially in environments such as enterprises, or public Wi-Fi hotspots