Storing secret key and preventing read access?

I am using RT 1064, I want to store a secret key during manufacturing (possibly in the OCOTP), which can only be read by DCP, and cannot be read from firmware. Assuming that the firmware is NOT encrypted/signed, is this possible/ how would I achieve this?