Updated on 2025-12-02 GMT+08:00

How Are Default Keys Generated?

A default key is automatically created by another cloud service using KMS, such as Object Storage Service (OBS). The alias of a default key ends with /default. Table 1 lists the default key aliases used by cloud services through KMS.

You can use the management console to query but cannot disable or schedule the deletion of Default Master Keys.

For example, when you upload an object on OBS, enable Server-Side Encryption, and set Encryption Key Type to Default, OBS will use KMS to generate a default key whose alias is obs/default.

Table 1 Default master keys

Alias

Cloud Service

obs/default

Object Storage Service (OBS)

evs/default

Elastic Volume Service (EVS)

ims/default

Image Management Service (IMS)

vbs/default

Volume Backup Service (VBS)

kps/default

Key Pair Service (KPS)

csms/default

Cloud Secret Management Service (CSMS)

rds/default

Relational Database Service (RDS)

dds/default

Document Database Service (DDS)