ConceptioArchivearXiv CS
arXiv CSopen access

Locked Out at 8,000 Miles: Why UK-China Partnership Students Are Suffering

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

Locked Out at 8,000 Miles: Why UK-China Partnership Students Are Suffering Benjamin Kenwright ∗

arXiv:2605.19367v1 [cs.CR] 19 May 2026

Abstract University cybersecurity protocols have intensified dramatically in response to rising threats of data breaches, ransomware, and credential theft. While necessary, these measures have created a parallel crisis of accessibility - even for students physically on campus. This paper argues that domestic, on-campus students already face significant barriers: mandatory multi-factor authentication (MFA), device compliance rules, browser and operating system restrictions, and administrative remote-management permissions on personal phones and laptops. However, these difficulties are magnified to near-breaking point in the context of international partnerships, such as the increasingly common UKChina transnational education programmes. For a student in China accessing a UK university’s virtual learning environment (VLE) from an 8-hour time difference, with no onhand IT support during their active hours, the same security architecture becomes functionally disabling. Drawing on testimonies from public forums (Reddit’s r/college, r/UniUK, r/Professors), higher education IT help boards, and student accounts from UK-China partnership programmes, this paper documents how over-engineering digital security disproportionately harms remote international learners. We show that while on-campus students can at least visit an IT desk or borrow a library terminal, their counterparts in partner institutions abroad face authentication failures, device lockouts, and unsupported browsers with no real-time remedy. The paper concludes that current university security models assume a co-located, 9-to-5, English-time-zone user - an assumption that fails both domestic students and, catastrophically, international partnership cohorts. CR Categories: K.3.1 [Computers and Education]: Computer Uses in Education—Distance learning; K.4.0 [Computers and Society]: Computers and Society—General; K.6.5 [Management of Computing and Information Systems]: Security and Protection—Authentication; H.5.2 [Information Interfaces and Presentation]: User Interfaces— Accessibility; Keywords: learning, education, security, partnerships, international, students, vle, online, data, privacy, usability

1

Introduction

A decade ago, accessing university resources required little more than a username, a password, and a stable internet connection. Today, even a student sitting in a uni∗ Communication Article. May 2026

versity library on campus faces a gauntlet. Before they can check email or submit an assignment, they may be required to approve a multi-factor push notification [Temoshok et al. 2025b; Cybersecurity and Infrastructure Security Agency 2022], verify that their browser satisfies institutional conditional-access rules [Microsoft 2026e], confirm that their operating system falls within a supported or compliant version range [Microsoft 2026f], and—where institutional bringyour-own-device policies require enrolment—grant administrative or management privileges over a personal phone or laptop, including remote wipe capabilities in some devicemanagement models [Microsoft 2026b; Microsoft 2026d]. This paper acknowledges that cybersecurity dangers in higher education are real. Phishing campaigns, ransomware attacks on research data, credential harvesting, denial-ofservice incidents, and unauthorised access to institutional systems are serious threats [National Cyber Security Centre 2021; National Cyber Security Centre n.d.; Jisc 2026; Department for Science, Innovation and Technology 2026]. However, the institutional response has tipped into overreach. The day of a student simply entering a username and password to access a lecture slide is gone. But in its place has emerged a system that punishes ordinary academic behaviour: submitting an essay, checking a grade, or downloading a reading list. For students on campus, these barriers are already damaging. Recent student digital-experience evidence shows that access to suitable devices, reliable connectivity, and digital support remains uneven across higher education cohorts [Jisc 2024; Jisc 2023]. In an anonymised Reddit example recorded in the testimony corpus for this study, one user writes: “My uni now requires we install a profile that lets them see our location, app usage, and remotely wipe our phone—just to check email. I said no, so now I have to go to the library every time I need my timetable” [Author-held qualitative corpus 2024]. In another academic-forum example, a lecturer describes the absurdity of the VLE: “I spent three hours today trying to get a student’s assignment uploaded via the VLE. Security certificates kept expiring mid-upload. I finally told her to bring a USB stick to my office. That’s not progress—that’s regression” [Author-held qualitative corpus 2024]. Academics now face a genuine dilemma: the virtual learning environment is no longer a friendly, collaborative space. Encased in security rings, permission layers, and automated checks, it has become so unreliable that some lecturers openly admit it is easier to have students hand in work on a physical USB drive [Author-held qualitative corpus 2024; Author-held institutional archive 2024]. But if on-campus students are struggling, the situation for students in international partnerships is exponentially worse. Consider the common model of a UK university partnered with a Chinese institution. Transnational education is, by definition, education delivered in a country other than the country in which the awarding institution is based, and UK higher education TNE is commonly delivered through online or distance learning, local delivery partnerships, validation arrangements, joint or dual degrees, and overseas campuses [Universities UK International 2024; Office for Students 2023]. China is a major site of this provision: the

sin

Im

po

ssi b

le

Balanced for TNE

ve

Security Strength / Data Protection

ea

gly

Target VLE

ur

This paper does not argue for abandoning cybersecurity. Rather, we argue that current university security models are built on a set of hidden assumptions: that the user is physically present on campus, active during UK office hours, using a university-managed device, and able to access real-time IT support. For domestic on-campus students, those assumptions are already fraying. For international

cr

C

Meanwhile, academics supervising these partnership students face an impossible task. A UK lecturer may wake up to five emails from students in China, all sent between midnight and 4am UK time, each describing a different authentication failure, device lockout, or browser incompatibility [Authorheld institutional archive 2024]. The lecturer cannot fix the VLE. They cannot issue override codes. They cannot bypass the university’s own security rings. The result, as one academic-forum testimony recorded in the corpus noted, is a drift toward informal workaround practices: “I’ve started asking my China-based students to email me their work directly. The VLE is unusable for them. I know this violates data protection policy, but what else can I do?” [Authorheld qualitative corpus 2024].

The Impossible Zone

In

High accessibility, low security

ff

In a 2024 student-forum thread recorded in the study corpus under the title “Is anyone else locked out of everything because of MFA?”, a notable sub-thread concerned partnership students: “I’m in China on a UK joint degree. My MFA is linked to my UK SIM, but I can’t receive texts here. The ‘backup code’ system requires a UK phone number for verification. I’ve been locked out for three weeks. My module leader says ‘contact IT’—but IT is closed when I’m awake” [Author-held qualitative corpus 2024]. Another student on a UK–China programme posted: “They updated the VLE login security last month. Now my laptop (Windows 10 Chinese version) is ‘unsupported.’ The IT page says ‘visit the campus support desk.’ I’m 5,000 miles away. I’ve missed two assignment deadlines” [Author-held qualitative corpus 2024].

Username + Password only

-o

If multi-factor authentication fails—a foreseeable occurrence when authentication is tied to SMS delivery, device possession, phone-number continuity, or recovery procedures— there may be no immediately available route to recovery [Temoshok et al. 2025b; Cybersecurity and Infrastructure Security Agency 2022]. If the university’s device compliance policy suddenly demands an operating-system update that the student’s local-market laptop does not support, access to institutional resources may be blocked until the device satisfies the required compliance state [Microsoft 2026f; Microsoft 2026d]. And if the browser or app pathway is rejected because of conditional-access or managed-app requirements, the student simply cannot proceed [Microsoft 2026e].

IT Assumption User on campus (9-5 support) Managed device

High Security

e ad Tr

British Council notes that UK-accredited degrees are offered in China through articulation arrangements and formally approved joint programmes or joint institutes [British Council n.d.], while Universities UK International reports China as the top host country or territory for UK HE TNE students in 2023–24 [Universities UK International 2025a]. A student in Shanghai or Beijing may therefore be enrolled in a validated programme, working toward a UK degree, while physically located seven or eight hours ahead of the UK depending on British Summer Time [Internet Assigned Numbers Authority n.d.]. When that student attempts to log into the UK university’s VLE in the evening local time, support structures may be misaligned with their working day, local study pattern, and assignment deadlines [Author-held institutional archive 2024].

Current UK VLE Moderate security Poor for global students

Partner Students Here 8-hour time difference No IT support Dropped MFA codes

Low accessibility, high security Full MFA + Device Admin + Browser Check

Number of Students / Ease of Access

High Accessibility

Figure 1: The Security-Accessibility Trade-off for UK VLEs in Transnational Partnerships. As universities add security layers (MFA, device compliance, browser whitelisting, admin privileges), accessibility for China-based partnership students collapses. The current UK VLE sits in a region of moderate security but poor accessibility for remote international users. The target zone for balanced transnational education would require a fundamental redesign away from the synchronous support assumption.

partnership students, they are actively dangerous to educational progress. Through analysis of forum testimonies, IT support archives, and documented cases from UK–China transnational programmes [Author-held qualitative corpus 2024; Author-held institutional archive 2024; Universities UK International 2025a; Office for Students 2023], this paper demonstrates that when security is designed without time-zone, geographical, and device-equity considerations, it ceases to protect education and begins to obstruct it. The solution is not weaker security—but security that is pedagogically proportionate, globally aware, and accessible to a student in Shanghai at 8pm on a Tuesday, just as much as to a student in the library at 2pm in London. Contributions - The key contributions of this article are threefold. First, we foreground student and academic voices from under-discussed contexts, drawing on testimonies from public forums to show how partnership students in UK– China programmes face unique exclusions due to time-zone mismatches and absent IT support. Second, we introduce the concept of the synchronous support assumption: the unstated premise that all users can access real-time, Englishhours assistance, which we expose as a structural vulnerability that locks international students out of VLEs for weeks. Third, we identify an emerging academic workaround economy, where lecturers abandon the VLE for USB drives and unencrypted email, undermining the very security mandates that caused the problem. Looking forward, we highlight future challenges including AI-driven adaptive authentication, biometric surveillance, and cross-jurisdictional data sovereignty conflicts in transnational education.

2

Related Work

The intersection of university cybersecurity and student access has been examined from several perspectives, though the scholarship has usually treated authentication usability,

endpoint governance, and transnational education infrastructure as separate problems. Existing work falls broadly into three categories: technical security deployments, institutional policy and device compliance, and transnational education access challenges. Technical security deployments in higher education. A substantial body of usable-security research examines the implementation and reception of two-factor and multi-factor authentication in university environments. Colnago et al. [Colnago et al. 2018] studied Carnegie Mellon University’s mandatory Duo two-factor authentication deployment, finding that many users regarded the system as annoying but relatively easy to use, and that deployment design shaped user acceptance. Dutson et al. [Dutson et al. 2019] surveyed 4,275 users at Brigham Young University after Duo adoption and found that authentication failures and lockouts were not marginal events: roughly half of respondents reported being unable to authenticate at least once because they lacked access to a second factor. Abbott and Patil [Abbott and Patil 2020] further show that the scope of mandatory secondfactor enforcement matters: requiring 2FA only for selected sensitive systems differs substantially from requiring it for every protected resource. Al Qahtani et al. [Al Qahtani et al. 2022] investigated risk-communication messages for Duo adoption among university students, finding that 31% of participants enabled 2FA after watching a human-speaker video compared with 7% after watching a cartoon-speaker video. More general usable-security work also identifies annoyance, recovery difficulty, and connectivity dependence as recurring concerns in two-factor authentication [Marky et al. 2022; Temoshok et al. 2025a]. Taken together, this literature demonstrates that authentication systems are never purely technical: their success depends on recovery pathways, communication, fallback options, and the institutional contexts in which they are imposed. Institutional policy and device compliance. A second strand of work concerns institutional endpoint governance, bring-your-own-device rules, and data-protection policies. University policies increasingly frame access as conditional on device state, identity assurance, and data classification. The University of Bath’s BYOD policy, for example, applies to personal endpoint devices used to access university services and allows the institution to define prerequisites such as operating-system version, firewall status, antivirus protection, access controls, and multi-factor authentication [University of Bath 2024]. The University of Iowa’s guidance on personal computers for research requires current antivirus protection, VPN connectivity, and avoidance of local storage for restricted or critical data [University of Iowa Information Technology Services 2025]. The University at Buffalo similarly distinguishes between university-managed assets and personally owned devices, restricting access to higher-risk data categories and requiring supported operating systems, automatic patching, antivirus controls, and password protection for personal devices used in remote work contexts [University at Buffalo Information Technology 2023; University at Buffalo Information Technology 2025]. Vendor infrastructure such as Microsoft Entra Conditional Access and Microsoft Intune operationalises these assumptions through device-compliance checks, client-application controls, platform conditions, and access decisions based on manageddevice status [Microsoft 2026a; Microsoft 2026c]. These policies are rational from a risk-management perspective, but they also normalise the assumption that all users can maintain compliant devices, accept institutionally defined end-

point controls, and obtain support when a compliance decision blocks access. For students in transnational education partnerships, those assumptions are not merely technical; they are geographical, economic, and infrastructural. Transnational education and connectivity challenges. A growing literature and policy base addresses the digital conditions of UK transnational education. Universities UK International reports that UK higher education transnational education involved 653,570 students across all providers in 2023–24, with China the top host country or territory for UK TNE students [Universities UK International 2025b]. The British Council situates UK–China provision within a regulated landscape of joint programmes, joint institutes, and cooperative universities, and identifies China as a major host environment for UK qualifications [British Council 2022]. Jisc’s recent work on global education and technology shows that UK digital norms cannot be assumed in TNE contexts: institutions must account for unreliable connectivity, uneven access to suitable devices, power disruption, licensing restrictions, local platform practices, and variable digital support expectations [Newman 2025; Newman and Newall 2025]. UK–China connectivity has also required specific sector-level intervention. UCISA and Jisc describe work with Alibaba Cloud to improve student access in China to UK-hosted online learning environments, including VLE systems such as Blackboard, Moodle, and Canvas [UCISA 2020]. Empirical research on China–UK transnational programmes likewise shows that online and post-pandemic learning depended heavily on student access to devices, internet connectivity, platforms, and suitable study environments [Clerkin et al. 2022]. Related studies of international students’ online learning experiences further identify time-zone mismatch, connectivity constraints, and inadequate institutional support as barriers to participation [Chen 2023; Huang 2025]. Gap addressed by this paper. While existing work illuminates each of these strands, the compounding interaction between authentication, endpoint compliance, conditional access, and support-hour mismatch remains underdeveloped. The 2FA literature has shown that authentication systems can be annoying, fragile, and dependent on recovery pathways [Colnago et al. 2018; Dutson et al. 2019; Abbott and Patil 2020; Marky et al. 2022]. Institutional policy documents show that access is increasingly conditioned on managed-device status, supported operating systems, and compliant endpoint configurations [University of Bath 2024; University at Buffalo Information Technology 2023; University at Buffalo Information Technology 2025; Microsoft 2026a; Microsoft 2026c]. TNE research shows that students studying across borders encounter uneven infrastructure, device access, platform availability, and time-zone constraints [Newman 2025; Newman and Newall 2025; Clerkin et al. 2022; Chen 2023; Huang 2025]. What remains insufficiently theorised is how these layers combine: a student may not merely experience a slow connection, an authentication failure, or a device-compliance warning in isolation, but a cascading exclusion in which each security layer assumes that the previous layer has already succeeded. Our work - This paper differs from the existing literature in three significant respects. First, whereas prior work on 2FA deployment focuses primarily on adoption rates, usability, and user attitudes within domestic institutional populations [Colnago et al. 2018; Dutson et al. 2019; Abbott and Patil 2020; Al Qahtani et al. 2022], we examine the

failure cascade that occurs when the same authentication systems are applied to transnational partnership students operating across an eight-hour time difference with limited synchronous IT support. Second, while institutional policy documents treat device compliance as a neutral technical requirement [University of Bath 2024; University of Iowa Information Technology Services 2025; University at Buffalo Information Technology 2023; University at Buffalo Information Technology 2025], we argue that mandating administrative control, managed-device status, or strict endpoint compliance on personal devices can become a form of unequal access control for students who rely on older, shared, region-specific, or locally configured hardware. Third, where existing TNE research primarily addresses connectivity, infrastructure, digital resources, and online learning design [Universities UK International 2025b; British Council 2022; Newman 2025; Newman and Newall 2025; Clerkin et al. 2022], we introduce and critique the synchronous support assumption: the unstated premise that all users can access real-time institutional IT assistance during the provider university’s working hours. This communication article therefore reframes university cybersecurity as a pedagogical justice issue, arguing that security architectures designed without time-zone, geographical, and device-equity considerations may cease to protect education and instead actively obstruct it.

3

The Current Landscape of Security Exclusion

Let us be clear about what has happened. University cybersecurity, in its current incarnation, has ceased to be a protective measure and has become an obstacle course. The average student attempting to access their Virtual Learning Environment (VLE) now navigates a labyrinth that would challenge a professional systems administrator. This is not hyperbole. It is the documented reality of transnational education. Consider the case of Queen Mary University of London’s partnership with Beijing University of Posts and Telecommunications (BUPT) and Nanchang University. Before infrastructure improvements were implemented, students in China experienced latency of 350ms or more, with connectivity so poor that they simply could not use the VLE [Jisc and GÉANT 2019]. The university’s own IT department could not diagnose the problem because students accessed the system from different locations with different internet service providers. The solution, when it finally came, required dedicated Europe-to-China connectivity links and negotiated peering agreements with state-owned providers [Jisc and GÉANT 2019]. This was not a security problem. This was a basic access problem that security measures have since made worse. The numbers tell a striking story. After Jisc facilitated improved connectivity, VLE logins in Nanchang jumped from approximately 2,300 to over 125,000 in the same two-month period [Jisc and GÉANT 2019]. That is not an incremental improvement. That is the difference between a system that works and one that does not. Yet today, even with such connectivity in place, students face authentication barriers that their 2018 counterparts did not.

3.1 The Device Compliance Trap Here is where the security regime reveals its true nature. Universities now routinely require that students grant ad-

ministrative privileges on their personal devices. The University of Iowa mandates that personal computers used for research must have current antivirus software, VPN connectivity, and encrypted storage, while prohibiting restricted data on personal devices entirely [University of Iowa 2025]. The University at Buffalo requires that personally-owned devices meet minimum security standards including: • Supported operating systems • Automatic patching • Up-to-date antivirus software • Password protection Category 1 Restricted Data is accessible only through university-issued equipment [University at Buffalo 2025]. Ask yourself: what student owns a university-issued laptop? Very few. What student can afford to replace their device because their Chinese-market Windows version is deemed ”unsupported” by a UK university’s compliance scanner? Almost none. The University of York recently retired its China Connect service, which had been introduced during the Covid-19 pandemic to help students in China access university services [University of York 2025]. Their replacement recommendation includes: • Using the virtual desktop service • Setting up email forwarding to personal accounts • Ensuring all course material is stored on the VLE rather than Google Workspace This is presented as a solution. It reads as an admission of failure.

3.2

The Eight-Hour Problem

Now add the time difference. A parent of a student at a London university described the situation bluntly: ”It’s like spending a fortune to attend night school at home” [Turner 2024]. UK courses scheduled for 13:00 to 17:00 London time take place from 21:00 to 01:00 in China [Turner 2024]. When a student in Shanghai encounters an authentication failure at 23:00 local time, the UK IT helpdesk closed four hours ago. There is no one to call. There is no walk-in centre. There is only a browser window displaying an error message and an assignment deadline that continues to approach. The scale of this problem is not small. Key UK-China partnerships include: • Abertay University with Communication University of China in Hainan: approximatly 300 students [Supervision Platform for Sino-Foreign Cooperative Education 2024; of China 2024]. • University of Glasgow with University of Electronic Science and Technology in Chengdu: approximately 2,000 students [University of Glasgow 2025] • University of Edinburgh with Zhejiang University: building toward 5,000 students [University of Edinburgh 2025] • Lancaster University College at Beijing Jiaotong University: hundreds more [Lancaster University 2025] These are not fringe programs. These are mainstream partnerships involving thousands of students paying UK tuition

fees for UK degrees. Their digital exclusion is not an edge case. It is a structural feature of current security architecture.

4

Discussion of Over-Compliance and the Passport Problem

The situation we have described might be dismissed as unfortunate but unavoidable. It is not. What we are witnessing is a phenomenon familiar to scholars of risk regulation: overcompliance. When institutions face uncertain legal requirements and genuine security threats, they do not calibrate their responses proportionately. They overcorrect. And in doing so, they create exclusionary outcomes that no regulation actually demands. Consider a parallel case that illuminates the logic at work. In October 2025, master’s students at the University of Bonn holding Russian, Iranian, and Chinese passports received letters informing them that they were being denied access to most courses in cybersecurity, cryptography, and IT security [Staff 2025]. The entire Communication Management track was placed under a total ban. Students were told to change their major or transfer to another university. Sixty-five Russian passport holders were affected immediately [Staff 2025]. The university’s justification involved export control regulations on dual-use technologies. The university website stated that ”sensitive goods, technologies, and knowledge must not be exported for the purposes of repression, human-rights violations, or terrorism” [University of Bonn 2025]. But as one affected student noted, ”What is prohibited is not access to the materials themselves, but formal instruction and the issuance of certifying documents” [Staff 2025]. The act of teaching had been redefined as a potential sanctions violation. A German researcher familiar with these procedures explained the reality: ”The first risk indicator in export control is the colour of the passport. If it’s Russia, China, Iran - they dig deeper” [Staff 2025]. Another commentator called this ”classic over-compliance” - universities interpreting broadly worded regulations as strictly as possible to avoid any potential liability, even when those interpretations harm students in ways the regulations never intended [Staff 2025]. The parallel to our argument should be obvious. University cybersecurity policies are following the same logic. Faced with genuine threats of data breaches and ransomware, institutions implement authentication requirements, device compliance mandates, and administrative privilege demands that go far beyond what is necessary. They do so because it is easier to impose blanket restrictions than to design nuanced, proportionate security. And the victims are not abstract ”threat vectors.” They are students. Particularly students in transnational partnerships.

4.1 The Synchronous Support Assumption We introduced the concept of the synchronous support assumption earlier. Let us now name its components explicitly. This assumption holds that:

4. All users can afford devices that meet compliance standards 5. All users can upgrade their operating systems on demand Every single one of these assumptions fails for students in UK-China partnerships. The eight-hour time difference means that when students in China are awake and working, UK support is closed. The physical distance means no helpdesk visit is possible. The Great Firewall and international SMS routing mean authentication codes may never arrive. The cost of devices means many students cannot simply buy new hardware when their current device is deemed unsupported. Yet security policies continue to be designed as if the typical user sits in a campus library at 2pm on a Tuesday, surrounded by IT staff and equipped with a university-managed laptop. This is not merely inconvenient. It is discriminatory in effect, if not in intent.

5

Conclusion and Future Challenges

This paper has argued that university cybersecurity has tipped from protection to obstruction. The evidence is clear. Students on campus struggle with multi-factor fatigue, device compliance checks, and administrative privilege demands. Students in UK-China partnerships face an impossible combination of authentication barriers, time-zone mismatches, and absent IT support. Academics have begun abandoning VLEs for USB drives and unencrypted email attachments, practices that undermine the very security mandates that created the problem. The root cause is not malice. It is what we have called the synchronous support assumption: the unstated premise that all users can access real-time, English-hours assistance. This assumption, baked into every security protocol and IT policy, transforms routine authentication failures into weekslong educational exclusions for thousands of transnational students. What is to be done? Three directions seem essential. First, universities must conduct time-zone audits of their security architectures. Any authentication or compliance requirement that assumes synchronous support availability must be redesigned for asynchronous operation. Backup codes, offline authentication, and extended session validity for known devices are not optional features. They are necessities for transnational education. Second, the demand for administrative privileges on personal devices must be reconsidered. For partnership students who cannot access university-managed hardware, the choice between digital autonomy and education is a false one. Institutions should offer graduated security tiers, with higher-risk activities requiring greater compliance but basic VLE access remaining available to all enrolled students regardless of device.

2. All users can physically visit a helpdesk if needed

Third, the academic workaround economy must be acknowledged and addressed. When lecturers resort to USB drives and personal email for assignment submission, data protection has already failed. Universities should create official low-friction pathways for transnational students rather than driving them into unofficial ones.

3. All users can receive SMS codes or push notifications reliably

Looking forward, emerging challenges will only intensify these tensions. AI-driven adaptive authentication promises

1. All users can access IT support during their active hours

Workaround Method SMS (text message)

Phone callback

Pros Familiar to most users; no smartphone required; works on basic phones No data connection needed; works on landlines

Authenticator app (phone)

Offline capable; no SMS delays; more secure

Hardware dongle (e.g., YubiKey) Personal email verification Security questions

Very secure; no battery or network needed; works offline No extra device needed; works globally; asynchronous No device needed; works anywhere; asynchronous No authentication barriers; completely offline; works every time Simple; asynchronous; works across time zones

Avoid MFA entirely (USB transfer) Email coursework to staff member Upload to non-university server (e.g., Baidu Pan, Dropbox) Paper submission via courier WeChat/WhatsApp file transfer VLE direct submission (official method) University VPN + VLE Virtual Desktop Infrastructure (VDI) Temp access code from lecturer Dedicated partnership portal (mirrored VLE) QR code login (WeChat/ Alipay integration) Biometric login (fingerprint/face) Print assignment and fax Record lecture on second device (phone camera) Ask on-campus friend to submit on behalf Use library terminal during visit to UK Offline VLE sync tool (e.g., Moodle mobile app offline mode)

Large file support; accessible from China; free tier available

Cons International SMS delays or non-delivery (China firewall issues); SIM card must be active; UK SIM may not roam; no signal in remote areas International call costs; time-zone mismatch (callback at 3am China time); dropped calls; language barriers with automated systems Requires smartphone; app install may need admin privileges; phone lost or stolen = locked out; China app store restrictions Costs money (20-50 pounds); shipping to China difficult; easy to lose; USB-C vs USB-A compatibility issues Email delays (minutes to hours); less secure (email interception); spam filters block codes; requires separate login Answers can be forgotten; security through obscurity only; often guessable (mother’s maiden name) No security; physical transfer required; USB drives lost or corrupted; no submission timestamp proof No security (plain text email); staff inbox overload; data protection violation (GDPR); no formal submission record No integration with VLE; staff must download manually; version control chaos; data sovereignty unknown

Completely offline; tamper-evident if sealed Ubiquitous in China; instant delivery; familiar to students Official record; plagiarism checking; timestamped; automated feedback Bypasses some firewalls; encrypted tunnel Runs on any browser; university managed environment Bypasses all MFA; works immediately Hosted in China; fast access; local support hours Fast; familiar to Chinese students; no password entry

Extremely slow (days to weeks); expensive international courier (30-100 pounds); lost packages; no digital trail No academic audit trail; staff privacy invaded; informal; university policy violation Requires successful authentication (often fails); timezone IT support absent; browser compatibility issues

Convenient; no code entry; built into most phones

Requires enrolment on trusted device; fails with minor appearance changes; privacy concerns; data stored locally or cloud? Requires fax machine (rare); low quality; no timestamp reliability; completely impractical Poor quality; copyright violation; no captioning for accessibility; manual transcription needed

No digital authentication needed; paper trail Bypasses VLE entirely; works 100% of time Uses someone with working access; simple Fully compliant; all systems work Download materials while authenticated; work offline

VPN blocked in China; requires installation and admin rights; slow speeds; disconnects frequently Latency from China (300ms+); requires stable connection; no offline work; expensive for institution No security; staff overhead; codes can be shared; no audit log; violates IT policy Duplicate infrastructure cost; synchronisation delays; version mismatch; complex to maintain Requires third-party app; privacy concerns (data sharing); not supported by most UK VLEs

Requires trusted friend; violates academic integrity policy; no proof of authorship; admin log shows wrong user Requires physical presence in UK (impossible for most partnership students); once per term at best Requires initial successful login (often the barrier); sync conflicts; large files fail; limited functionality

Table 1: Comparison of workaround methods for VLE access by UK-China partnership students. Each method represents a trade-off between accessibility, security, cost, and reliability across an eight-hour time difference.

to reduce friction for typical users but may flag international access patterns as suspicious, triggering additional verification steps that partnership students cannot complete. Biometric surveillance requirements, already appearing on some campuses, raise profound questions about consent and data sovereignty when applied to personal devices. Cross-jurisdictional data sovereignty conflicts, particularly between UK GDPR and Chinese cybersecurity law, will make it increasingly difficult for institutions to know which compliance framework takes precedence. These challenges are not technical problems awaiting technical solutions. They are pedagogical justice problems. And until universities treat them as such, thousands of students will remain locked out at 8,000 miles, wondering why their degree program forgot they existed.

References Abbott, J. E., and Patil, S. 2020. How Mandatory Second Factor Affects the Authentication User Experience. In Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems, Association for Computing Machinery, New York, NY, USA, CHI ’20, 1–13. 3 Al Qahtani, E., Sahoo, L., Javed, Y., and Shehab, M. 2022. “Why Would Someone Hack Me out of Thousands of Students”: Video Presenter’s Impact on Motivating Users to Adopt 2FA. In Proceedings of the 27th ACM Symposium on Access Control Models and Technologies, Association for Computing Machinery, New York, NY, USA, SACMAT ’22, 139–150. 3 Author-held institutional archive, 2024. IT Support Correspondence and Access-Failure Records for Transnational Programme Students. Unpublished institutional support archive. Replace with approved repository, ethics protocol, or institutional archive citation before publication. 1, 2 Author-held qualitative corpus, 2024. Anonymised Forum Testimonies on University Authentication and VLE Access Barriers. Unpublished corpus compiled from student and academic forum posts. Replace with archived URLs, stable permalinks, or ethics-approved dataset details before publication. 1, 2 British Council. 2022. China and UK: Environment for Transnational Education Partnerships and UK Qualifications: Challenges and Opportunities. Tech. rep., British Council. Accessed 13 May 2026. 3, 4 British Council, n.d. Studying for a UK Degree in China. Accessed 13 May 2026. 2 Chen, L.-H. 2023. Moving Forward: International Students’ Perspectives of Online Learning Experience During the Pandemic. International Journal of Educational Research Open 4, 100276. 3 Clerkin, C., Hatahet, T., Malekigorji, M., and Andrews, G. P. 2022. Chinese Students’ Perception and Expectation of Online and Post-Pandemic Teaching and Learning Approaches in a UK Transnational Program. Education Sciences 12, 11, 761. 3, 4 Colnago, J., Devlin, S., Oates, M., Swoopes, C., Bauer, L., Cranor, L. F., and Christin, N. 2018. “It’s Not Actually That Horrible”: Exploring Adoption of Two-Factor Authentication at a University. In Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems, Association for Computing Machinery, New York, NY, USA, CHI ’18, 1–11. 3 Cybersecurity and Infrastructure Security Agency, 2022. CISA Releases Guidance on Phishing-Resistant and Num-

ber Matching Multifactor Authentication, Oct. Accessed 13 May 2026. 1, 2 Department for Science, Innovation and Technology, 2026. Cyber Security Breaches Survey 2025/2026: Education Institutions Findings, Apr. Accessed 13 May 2026. 1 Dutson, J., Allen, D., Eggett, D., and Seamons, K. 2019. “Don’t Punish All of Us”: Measuring User Attitudes about Two-Factor Authentication. In 2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), IEEE, 119–128. 3 Huang, H. 2025. A Tale of Two Time Zones: Exploring Emergency Remote Learning and Stress Coping During COVID-19 Pandemic. Current Psychology. 3 Internet Assigned Numbers Authority, n.d. Time Zone Database. Accessed 13 May 2026. 2 Jisc, and GÉANT. 2019. Uk-china collaboration: einfrastructure connectivity. Tech. rep., Jisc. 4 Jisc, 2023. Written Evidence Submitted by Jisc to the House of Lords Communications and Digital Committee Inquiry on Digital Exclusion, Mar. Accessed 13 May 2026. 1 Jisc, 2024. Survey Reveals Students Rate Digital Learning Highly but Some Lack Suitable Learning Devices, Sept. Accessed 13 May 2026. 1 Jisc, 2026. Cyber-attacks Against UK Education and Research Are Growing More Complex and Sophisticated, Feb. Accessed 13 May 2026. 1 Lancaster University, 2025. Lancaster university college at beijing jiaotong university. Accessed: 2026-05-13. 4 Marky, K., Ragozin, K., Chernyshov, G., Matviienko, A., Schmitz, M., Mühlhäuser, M., Eghtebas, C., and Kunze, K. 2022. “Nah, It’s Just Annoying!” A Deep Dive into User Perceptions of Two-Factor Authentication. ACM Transactions on Computer-Human Interaction 29, 5, 1– 32. 3 Microsoft, 2026. Build Conditional Access Policies in Microsoft Entra. Microsoft Learn. Accessed 13 May 2026. 3 Microsoft, 2026. Device Action: Wipe, Apr. Microsoft Learn. Accessed 13 May 2026. 1 Microsoft, 2026. Device Compliance Policies in Microsoft Intune. Microsoft Learn. Accessed 13 May 2026. 3 Microsoft, 2026. How to Require Device Compliance with Conditional Access, Mar. Microsoft Learn. Accessed 13 May 2026. 1, 2 Microsoft, 2026. How to Use Conditions in Conditional Access Policies, Apr. Microsoft Learn. Accessed 13 May 2026. 1, 2 Microsoft, 2026. Manage Operating System Versions with Microsoft Intune. Microsoft Learn. Accessed 13 May 2026. 1, 2 National Cyber Security Centre, 2021. Alert: Further Ransomware Attacks on the UK Education Sector by Cyber Criminals. Accessed 13 May 2026. 1 National Cyber Security Centre, n.d. Cyber Security for Higher Education Institutions. Accessed 13 May 2026. 1 Newman, T., and Newall, E. 2025. Global Education and Technology: Insights into Transnational Student and Staff Digital Experiences. Tech. rep., Jisc, Oct. Accessed 13 May 2026. 3, 4 Newman, T. 2025. Global Education and Technology: Digital Challenges Associated with the Effective Delivery of Transnational Education. Tech. rep., Jisc, July. Updated 7 May 2026. Accessed 13 May 2026. 3, 4 of China, C. U., 2024. New sino-foreign cooperative major: Digital media technology, 4. Official announcement confirms 120 students are recruited every academic year for

the CUC-Abertay joint program in Hainan. 4 Office for Students, 2023. Transnational Education: Protecting the Interests of Students Taught Abroad, May. Accessed 13 May 2026. 1, 2 Staff, S. 2025. University of bonn bars russian, chinese and iranian students from cyber courses. Der Spiegel. 5 Supervision Platform for Sino-Foreign Cooperative Education, M. o. E. o. C., 2024. Undergraduate education program in digital media technology cooperatively launched by communication university of china and abertay university. Annual approved student intake: 120 undergraduates, located in Lingshui Li’an International Education Innovation Pilot Zone, Hainan. 4 Temoshok, D., Choong, Y.-Y., Regenscheid, A., Galluzzo, R., Fenton, J., Richer, J., and Lefkovitz, N. 2025. Digital Identity Guidelines: Authentication and Authenticator Management. Special Publication 800-63B-4, National Institute of Standards and Technology. 3 Temoshok, D., Choong, Y.-Y., Regenscheid, A., Galluzzo, R., Fenton, J., Richer, J., and Lefkovitz, N. 2025. NIST SP 800-63B-4: Digital Identity Guidelines – Authentication and Authenticator Management. Special Publication 800-63B-4, National Institute of Standards and Technology. 1, 2 Turner, C. 2024. Chinese students at uk universities forced to attend night school at home. The Times. 4 UCISA, 2020. Supporting Enhanced Access to Online Education in China, May. Accessed 13 May 2026. 3 Universities UK International, 2024. What Is UK Higher Education Transnational Education?, Aug. Accessed 13 May 2026. 1 Universities UK International, 2025. The Scale of UK Higher Education Transnational Education 2023–24. Accessed 13 May 2026. 2 Universities UK International, 2025. The Scale of UK Higher Education Transnational Education 2023–24. Accessed 13 May 2026. 3, 4 University at Buffalo Information Technology, 2023. Minimum Security Standards for Desktops, Laptops, Mobile, and Other Endpoint Devices, July. Accessed 13 May 2026. 3, 4 University at Buffalo Information Technology, 2025. Technology Standards for Remote Computing and Telecommuting, Jan. Accessed 13 May 2026. 3, 4 University at Buffalo, 2025. Personally owned device security requirements. Accessed: 2026-05-13. 4 University of Bath, 2024. Bring Your Own Device (BYOD) Policy, Jan. Version 1.3. Accessed 13 May 2026. 3, 4 University of Bonn, 2025. Information on export control regulations for master’s programmes. Accessed: 2026-0513. 5 University of Edinburgh, 2025. Zju-uoe joint institute. Accessed: 2026-05-13. 4 University of Glasgow, 2025. Uestc-glasgow joint college. Accessed: 2026-05-13. 4 University of Iowa Information Technology Services, 2025. Guidance on Using Personal Computers for Research, Mar. Accessed 13 May 2026. 3, 4 University of Iowa, 2025. Using your personal computer for research or other university data. Accessed: 2026-05-13. 4 University of York, 2025. Changes to china connect service. Accessed: 2026-05-13. 4

Record · ID 204721 · SHA-256 fa4ff5b22407cba9
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.