Summary

  • Klaas Wierenga initiated eduroam at SURFnet in 2002 around a strict division of responsibility: the home institution authenticates its user, while the visited institution decides whether and how that user may enter its network.
  • IEEE 802.1X, EAP and a hierarchy of RADIUS proxies allowed an authentication exchange to reach the home institution without turning the roaming service into a global credential store. The hierarchy routed trust; it did not become the final identity authority.
  • The design scaled because institutions retained powers they were unwilling to surrender. Its continuing costs are federation governance, realm and certificate hygiene, proxy operation, privacy choices and abuse coordination.

The visitor whom the local network cannot know

SURF uses a simple example to explain eduroam: a Delft University of Technology student arrives at a university in Cape Town. Cape Town can see a device asking for access, but its own account system has no basis for authenticating the student. Delft has that basis, but Delft cannot decide what a foreign campus should allow on its network. An ordinary hotspot account resolves the mismatch by creating a new local identity. A globally central service could resolve it by taking custody of everyone’s identity. eduroam chose neither.

The visited network sends an authentication request towards the user’s home institution. The home institution checks the credential and returns a result. The visited network then authorizes access under its own policy. Authentication and authorization, often collapsed into one login screen, remain separate decisions held by separate organisations.

That separation is the centre of Wierenga’s achievement. The visible product is convenient Wi-Fi roaming. The underlying invention is a settlement about institutional authority: who may know the password, who may assert that an account is valid, who may admit a device, and who remains accountable when something goes wrong.

A proposal before there was a service

The official eduroam history traces the project to the TERENA Task Force on Mobility and an email Wierenga sent from SURFnet on 30 May 2002 proposing inter-NREN roaming. Researchers and students were becoming more mobile, yet every visit to another university produced another registration procedure, temporary account or improvised guest arrangement. Wierenga had also worked on secure wireless access and the first generation of federated identity systems at the Dutch research and education network.

According to SURF, he asked intern Paul Dekkers to build a pilot around federated identity. The Dutch experiment succeeded. A cross-border pilot brought together SURFnet, the University of Southampton, Portugal’s FCCN and Zagreb’s Srce, with other national research and education networks following. GÉANT adopted the work for international development in 2003. Its projects supplied the testing, agreements and operational tools that a clever campus demonstration could not provide by itself.

This chronology matters because eduroam was not a central platform released by a single vendor. The service grew as institutions made their own infrastructure available under common technical and policy rules. GÉANT’s account of Wierenga’s 2019 Internet Hall of Fame induction emphasizes the collective labour that followed the initiating idea. The useful authorship claim is therefore precise: Wierenga framed and advanced the architecture; many hundreds of operators made it dependable.

Three technical options, three allocations of trust

RFC 7593 records that the project tried three architectural families. A virtual private network could protect traffic, but did not offer an administratively scalable roaming arrangement. A captive portal could be deployed widely, yet it made secure credential handling difficult. The chosen combination—IEEE 802.1X at the network edge, EAP for authentication exchanges and RADIUS for federation—fit the requirements of security, scale, deployability and open standards more closely.

The portal problem was not merely an inelegant browser interruption. In a federation of unfamiliar campuses, a user could not reliably distinguish a legitimate local password page from an imitation. If every visited institution collected the home password, credential custody would be distributed to precisely the parties that did not need it. A VPN, meanwhile, could create a secure tunnel without solving how thousands of institutions should discover, trust and administer one another.

The selected design gave the device a logical authentication conversation with its home identity provider through tunneled EAP methods or EAP-TLS. The visited access equipment and intervening RADIUS servers relayed the exchange. Private credential material remained protected for the home side, while an accept or reject result returned to the visited side. A successful response did not command the visited campus to open everything; local authorization and network policy still applied.

The hierarchy was a route, not a vault

A user identity includes a realm. RADIUS proxies use that realm to send the request up and across an organisational, national and international hierarchy towards the appropriate home provider. RFC 7593 illustrates a Dutch visitor at the University of Tennessee: the request can travel from the campus through an .edu layer, a root, an .nl layer and SURFnet before reaching home. The response returns along the path.

The analogy to DNS is useful but limited. The hierarchy reduces the need for every university to maintain bilateral configuration with every other university. It creates a transitive trust path. It does not mean that the upper layers contain a global table of passwords or make the final identity decision. The home institution remains the identity authority because it has the account relationship; the visited institution remains the resource authority because it owns the network being used.

This is why the phrase “the credential stayed home” should be read as a control statement. Authentication messages crossed borders. Proxies necessarily handled routing information, and the visited network observed a local session. But the private password did not have to become common federation property, nor did a new global operator have to enroll the student.

Distribution transferred work rather than abolishing it

The first hierarchy carried its own fragility. Static routing tables, RADIUS over UDP, pairwise shared secrets, aggregation bottlenecks and manually synchronized routes created operational burdens. A federation is not self-executing simply because its diagram lacks a central database. Participants needed documentation, configuration standards, diagnostics, monitoring, metering and a process for investigating misuse.

Later work improved the fabric without reversing its original allocation of authority. RADIUS over TLS strengthened links, while RFC 7585 specified dynamic peer discovery through DNS. A connection could be upgraded without a federation-wide flag day. The network became less dependent on manually maintained routes while the home institution still authenticated and the visited institution still authorized.

The political economy is visible here. Institutions joined because they could gain reciprocal reach without transferring their entire identity system to a new sovereign. Yet reciprocity also required them to operate their part well enough for strangers to rely on it. The architecture minimized the new authority demanded from each member; it did not eliminate obligations.

Privacy has an edge, not a halo

The 2006 technical specification treats the roaming infrastructure as inherently unsafe and makes end-to-end protection of sensitive authentication data a design principle. Anonymous outer identities can also reduce the ability of a visited site or intermediate proxy to correlate a named person across sessions. Those safeguards are substantial, but they are not a promise of invisibility.

RFC 7593 notes the trade-off between anonymity and the ability to trace abuse or diagnose faults. The visited network still sees the traffic and device activity occurring on its own infrastructure, subject to its controls and applicable law. The home provider knows the account it authenticated. Realm data may disclose an affiliation even when a username is concealed. Accurate analysis therefore avoids both extremes: eduroam is neither a central surveillance database nor a privacy shield that removes local accountability.

Wierenga’s reusable idea

The Internet Hall of Fame credits Wierenga with inventing eduroam. The claim is strongest when “invention” describes the arrangement he set in motion, not ownership of every component. 802.1X, EAP and RADIUS existed as open standards. Universities already ran identity systems and networks. Wierenga’s move was to assemble them around an institutional invariant: trust a person’s home organisation to know the person, and trust the visited organisation to govern the resource.

That invariant made growth cumulative. Adding another campus did not require a global service to absorb another password database or every existing member to negotiate a fresh pairwise guest system. It required the new participant to implement the common edge, join the hierarchy and accept federation responsibilities. The credential stayed home; the ability to roam travelled.

Sources

  1. eduroam, “From an idea to a global service”
  2. eduroam FAQs
  3. eduroam, “How does eduroam work?”
  4. GÉANT, Inter-NREN Roaming Technical Specification
  5. GÉANT, eduroam Policy Service Definition
  6. Internet Hall of Fame, Klaas Wierenga
  7. RFC 7585, Dynamic Peer Discovery for RADIUS/TLS
  8. RFC 7593, The eduroam Architecture for Network Roaming
  9. GÉANT, “Klaas Wierenga inducted into the Internet Hall of Fame”
  10. SURF, “eduroam: the killer app for the 21st-century internet”