EAP SIM and AKA identities.
From: Suresh (sureshvvintotoinc.com)
Date: Wed, 6 Apr 2005 03:06:27 -0400 (EDT)

Hi
I have a small clarification in the identities and user names used in the EAP-SIM and AKA implementations.
When ever a client needs to send fill in the AT_IDENTITY attribute, it has to fill in the complete identity, and the identity may or may not have a realm portion.
The format of the permanent user name is 0|IMSI and 1|IMSI for the AKA and SIM respectively.
It is also given that

   The EAP server MAY use the leading "1" as a hint to try EAP-SIM as
   the first authentication method during method negotiation, rather
   than for example EAP/AKA.  The EAP-SIM server MAY propose EAP-SIM
   even if the leading character was not "1".

for EAP-AKA.

I could not understand how user name is sent to the EAP-Server, in actual, complete identity is sent in the AT_IDENTITY attribute and not just the user name.

regards,
Suresh
                                                                                                                                         

Results generated by Tiger Technologies using MHonArc.