An authentication apparatus includes a biometric data acquirer configured to acquire fingerprint data and an electrocardiogram (ECG) waveform of a user, and a humidity level acquirer configured to acquire a humidity level of skin of the user. The apparatus further includes a similarity extractor configured to adjust a first similarity between the fingerprint data and reference fingerprint data of a pre-registered user, and a second similarity between the ECG waveform and a reference ECG waveform of the pre-registered user, based on the humidity level, and extract a combined similarity based on the adjusted first similarity and the adjusted second similarity. The apparatus further includes an authenticator configured to authenticate whether the user is the pre-registered user based on the combined similarity.