'Authorised devices' (with a certificate/token authentication), with a -backup- password or other method. Every device has its own MAC address, why not take advantage of that? Of course, that doesn't eliminate -stealing- the device... but at least you can't do that from a distance ; ).

