The security of handover key management in Long Term Evolution(LTE)/System Architecture Evolution(SAE) has been a popular topic in recent years. In this paper we first describe the security architecture and key hierarchy of LTE/SAE, clarifying security requirements of key management in handover. Next, we analyze security of key management in X2 handover(intra-MME handover), and point out the current key management mechanism in X2 handover only satisfy two-hops forward security and one-hop backward security, but not onehop security. And then, aimed at the security vulnerability of lacking one-hop forward security in current X2 handover key management, we proposed a new scheme for key management in X2 handover based on ciphering some key parameters with the local master root key. At last, the proposed new scheme is analyzed under three adversary models. The analysis shows that one-hop forward security and one-hop backward security could be maintained in our new proposal.