<p>A cryptographic-key updating method and system, the method includes that: a card issuer management platform informs a smart card to update an issuer security domain cryptographic-key in the case of that the issuer security domain cryptographic-key of the smart card is unexpired (S202); the smart card establishes a connection with the card issuer management platform, and establishes a secure channel through the connection (S204); the smart card and the card issuer management platform implement the updating operation of the issuer security domain cryptographic-key through the secure channel (S206). The updating of the smart card issuer security domain can be high-speed, real-time and safely implemented through the above technical solution.</p>