I would also suggest watching Karsten Nohl/SRLabs security research into JavaCard and the "state of the SIM" from the Observe Make Hack 2013 camping conference, which is available at: https://archive.org/details/D4T204201301031400SimCardExploit... and his article at https://srlabs.de/rooting-sim-cards/