Nothing really prevents you from doing double encryption in OHTTP. The gateway decrypts once, and the origin (target resource) decrypts a second time. HPKE is a good choice to use for the inner layer.