OCB mode seems to represent the state of the art in authenticated encryption modes, largely due to its speed – it is faster than GCM even when GCM has hardware support. Its only drawbacks seem to be that it requires frequent rekeying ( every $~2^{13}$ blocks if one wants to match GCM auth robustness when very large amounts of data are transmitted) and is patented (a dealbreaker for many applications).
Are there any other modes that can match OCB for speed?