This document describes the architecture of the eduroam service for
federated (wireless) network access in academia. The combination of
IEEE 802.1X, the Extensible Authentication Protocol (EAP), and RADIUS
that is used in eduroam provides a secure, scalable, and deployable
service for roaming network access. The successful deployment of
eduroam over the last decade in the educational sector may serve as
an example for other sectors, hence this document. In particular,
the initial architectural choices and selection of standards are
described, along with the changes that were prompted by operational
experience.