hi mike yes u can easily do that.
it;s called hair pinning vpns on the asa.
but in that case on the asa too u will have to have 4 vpn tunnels terminating on each remote branch.
but on the branch routers u can configure it that for sending traffic to other bracnhes should be ipsec protected and send to the asa as the central ipsec hub.the asa will then decrypt the packet and re-encrypt the packet and forward if to the other branch.
so on ur branches u will have only a single vpn tunnel to the asa but it will protect all the traffic from that branch to the asa and as well as for other branches.
i guess u are looking for this kind of solution.
hope this helps
regards
sushil