I'm confused. Why can't they remote login to a box with their home directory encrypted?
Is it not enough to have the pubkey stored outside their home? e.g.
# /etc/ssh/sshd_config
AuthorizedKeysFile /var/ssh/%u/authorized_keys
Once they authenticate they can run cryptsetup or what-have-you. To me that sounds way better than having randos guess your luks passphrase.