With the YubiKey, there is an interesting possibility to set your own AES PSK in the token: <a href="http://www.yubico.com/personalization-tool" rel="nofollow">http://www.yubico.com/personalization-tool</a> . That allows you to depend only on your own server infrastructure and not the one from a third-party like YubiKey. (Might be useful seeing the recent RSA security issue)