OBS allows you to encrypt objects with server-side encryption so that the objects can be securely stored in OBS.
When you upload an object to a bucket with server-side encryption disabled, you can separately configure server-side encryption for the object. If the bucket has server-side encryption enabled, the object you upload inherits encryption from the bucket by default. You can also configure new encryption for the object.
In the region where OBS is deployed, the KMS Administrator permission has been added to the user group. For details about how to add permissions, see the IAM User Guide.
If the bucket has server-side encryption configured, the object you upload will inherit encryption from the bucket by default.
Figure 1 Encrypting an object to be uploaded

After the object is uploaded, you can view its encryption status on its details page.