Probably something like OATH (as used by google authenticator and similar software) or a yubikey. With yubikey you can even get your own HSM for the authentication server.
Thanks. I had heard about yubikey. will def check it out.
Might be worth to note that the YubiKey authors did mess up quite badly at one point in time: