An EAP method (RFC 5216) in which both the client and the server authenticate with X.509 certificates inside a TLS handshake — no passwords are exchanged at all. It is widely regarded as the strongest common network authentication method because there is no reusable credential to phish or relay. It requires a PKI to issue client certificates, which is why it is usually deployed alongside SCEP or another enrolment mechanism.
EAP-TLS
EAP Transport Layer Security