By default IBM COS are encrypted by using randomly generated keys and all-or-nothing-transform (AONT). My question is: are these keys only generated once, or are they rotate