A method is disclosed for communicating a security credential within a
network device authentication conversation. An authenticator that is
coupled to a supplicant through a network performs a first message
conversation resulting in creating a security context that is known to
the authenticator and the supplicant. A second message conversation is
initiated. The second message conversation is cryptographically protected
using the same security context. A security credential is provided to the
supplicant in the second message conversation. The second message
conversation and first message conversation are then concluded. Specific
embodiments can bootstrap digital certificates, public/private key pairs,
and other credentials to supplicants, in-band, within an EAP-SIM or
EAP-AKA conversation and without initiating a new session or exchanging
special-purpose keys to protect distribution of the credentials.